{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:O5GV3SCKOEQMRDCYJKR25DLXXF","short_pith_number":"pith:O5GV3SCK","schema_version":"1.0","canonical_sha256":"774d5dc84a7120c88c584aa3ae8d77b96e000db5363d4e1c50f5cfef713f6779","source":{"kind":"arxiv","id":"2404.17399","version":2},"attestation_state":"computed","paper":{"title":"Evaluations of Machine Learning Privacy Defenses are Misleading","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Florian Tram\\`er, Jie Zhang, Michael Aerni","submitted_at":"2024-04-26T13:21:30Z","abstract_excerpt":"Empirical defenses for machine learning privacy forgo the provable guarantees of differential privacy in the hope of achieving higher utility while resisting realistic adversaries. We identify severe pitfalls in existing empirical privacy evaluations (based on membership inference attacks) that result in misleading conclusions. In particular, we show that prior evaluations fail to characterize the privacy leakage of the most vulnerable samples, use weak attacks, and avoid comparisons with practical differential privacy baselines. In 5 case studies of empirical privacy defenses, we find that pr"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2404.17399","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-04-26T13:21:30Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"731411b8139c430b6b6207e2420276e13d2d2b34c80ec76c734c2c5e2b83c590","abstract_canon_sha256":"9eb6147106ae5b63040b508eebb7467e8d9f9acb087f0ce400d2565fc7a4234e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:03:40.471696Z","signature_b64":"nfeH/Q9VmGVDONYwZG6gIP8bTNKJ1Mxa6jzobr4JI+825NKGmE29hBmdyP/v3/SvLkcDCjlDOXaYyh6QpAL+AQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"774d5dc84a7120c88c584aa3ae8d77b96e000db5363d4e1c50f5cfef713f6779","last_reissued_at":"2026-07-05T09:03:40.471173Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:03:40.471173Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Evaluations of Machine Learning Privacy Defenses are Misleading","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Florian Tram\\`er, Jie Zhang, Michael Aerni","submitted_at":"2024-04-26T13:21:30Z","abstract_excerpt":"Empirical defenses for machine learning privacy forgo the provable guarantees of differential privacy in the hope of achieving higher utility while resisting realistic adversaries. We identify severe pitfalls in existing empirical privacy evaluations (based on membership inference attacks) that result in misleading conclusions. In particular, we show that prior evaluations fail to characterize the privacy leakage of the most vulnerable samples, use weak attacks, and avoid comparisons with practical differential privacy baselines. In 5 case studies of empirical privacy defenses, we find that pr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2404.17399","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2404.17399/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2404.17399","created_at":"2026-07-05T09:03:40.471232+00:00"},{"alias_kind":"arxiv_version","alias_value":"2404.17399v2","created_at":"2026-07-05T09:03:40.471232+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2404.17399","created_at":"2026-07-05T09:03:40.471232+00:00"},{"alias_kind":"pith_short_12","alias_value":"O5GV3SCKOEQM","created_at":"2026-07-05T09:03:40.471232+00:00"},{"alias_kind":"pith_short_16","alias_value":"O5GV3SCKOEQMRDCY","created_at":"2026-07-05T09:03:40.471232+00:00"},{"alias_kind":"pith_short_8","alias_value":"O5GV3SCK","created_at":"2026-07-05T09:03:40.471232+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.19360","citing_title":"SoK: Can Synthetic Images Replace Real Data? A Survey of Utility and Privacy of Synthetic Image Generation","ref_index":3,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF","json":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF.json","graph_json":"https://pith.science/api/pith-number/O5GV3SCKOEQMRDCYJKR25DLXXF/graph.json","events_json":"https://pith.science/api/pith-number/O5GV3SCKOEQMRDCYJKR25DLXXF/events.json","paper":"https://pith.science/paper/O5GV3SCK"},"agent_actions":{"view_html":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF","download_json":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF.json","view_paper":"https://pith.science/paper/O5GV3SCK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2404.17399&json=true","fetch_graph":"https://pith.science/api/pith-number/O5GV3SCKOEQMRDCYJKR25DLXXF/graph.json","fetch_events":"https://pith.science/api/pith-number/O5GV3SCKOEQMRDCYJKR25DLXXF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF/action/storage_attestation","attest_author":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF/action/author_attestation","sign_citation":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF/action/citation_signature","submit_replication":"https://pith.science/pith/O5GV3SCKOEQMRDCYJKR25DLXXF/action/replication_record"}},"created_at":"2026-07-05T09:03:40.471232+00:00","updated_at":"2026-07-05T09:03:40.471232+00:00"}