{"id":"W3046102592","doi":"10.48550/arxiv.2007.14321","title":"Label-Only Membership Inference Attacks","year":2020,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":98,"is_retracted":false,"has_abstract":true,"ca_institutions":"Vector Institute; University of Toronto","funders":"","keywords":"Inference; Computer science; Exploit; Outlier; Adversary; Robustness (evolution); Machine learning; Data mining; Low Confidence; Artificial intelligence; Computer security; Psychology","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.01027972,0.001364524,0.001735358,0.000975725,0.001778466,0.003513565,0.003368131,0.004170316,0.003030516],"category_scores_gemma":[0.05336929,0.0008137298,0.002158374,0.001153369,0.003605434,0.01051482,0.009472922,0.007512052,0.001372973],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.002456009,"about_ca_system_score_gemma":0.001576814,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0008840966,"about_ca_topic_score_gemma":0.0007271271,"domain_scores_codex":[0.9805468,0.006555672,0.001090894,0.003402039,0.006712906,0.001691677],"domain_scores_gemma":[0.9486164,0.02149781,0.00393222,0.02331312,0.001944962,0.0006955282],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.002599692,0.0006246387,0.02015023,0.0005020075,0.0006001452,0.001204303,0.002720339,0.2320286,0.04140522,0.4302164,0.01935941,0.2485889],"study_design_scores_gemma":[0.00009992302,0.0002201112,0.001782439,0.00009127078,0.00009053683,0.000826146,0.0002627484,0.7126625,0.03485723,0.238565,0.01045698,0.00008507079],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1184661,0.0004926199,0.8596359,0.004268386,0.0001823827,0.0003544119,0.0009199105,0.003762536,0.01191766],"genre_scores_gemma":[0.9348824,0.000129288,0.06019276,0.001184279,0.0001143361,0.0001865229,0.0003759394,0.0002149769,0.0027195],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.01027972,"threshold_uncertainty_score":0.05436498,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.140592867580672,"score_gpt":0.2412268005431942,"score_spread":0.1006339329625223,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}