{"id":"W4387928556","doi":"10.48550/arxiv.2310.13786","title":"Fundamental Limits of Membership Inference Attacks on Machine Learning Models","year":2023,"lang":"en","type":"preprint","venue":"arXiv (Cornell University)","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":2,"is_retracted":false,"has_abstract":true,"ca_institutions":"","funders":"Institut Universitaire de France; Agence Nationale de la Recherche","keywords":"Overfitting; Inference; Computer science; Machine learning; Statistical inference; Artificial intelligence; Point (geometry); Statistical model; Data mining; Mathematics; Artificial neural network; Statistics","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.03715299,0.00167137,0.002704377,0.002280326,0.002861256,0.006357197,0.004230884,0.005172231,0.003486329],"category_scores_gemma":[0.2196363,0.001637155,0.002014826,0.001605703,0.01159631,0.01369785,0.01082445,0.01244111,0.0005872343],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.004462025,"about_ca_system_score_gemma":0.002635641,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0007256641,"about_ca_topic_score_gemma":0.0004514989,"domain_scores_codex":[0.9723551,0.01531105,0.001135682,0.003298993,0.006105823,0.001793253],"domain_scores_gemma":[0.6329628,0.3222179,0.0135791,0.0240852,0.004278886,0.002876084],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0003062611,0.0001102014,0.002438972,0.000203083,0.000137937,0.0002118674,0.000432818,0.2115395,0.002341263,0.7640508,0.002095478,0.01613186],"study_design_scores_gemma":[0.00003378886,0.00008604368,0.0003348736,0.00006826279,0.0000177353,0.0001452049,0.00005565022,0.4522479,0.001155799,0.5450811,0.0007386224,0.00003506496],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.09726758,0.001366078,0.8747936,0.007957512,0.000168631,0.000188744,0.0003291254,0.0006493868,0.01727936],"genre_scores_gemma":[0.94712,0.0009885218,0.04791167,0.0009957538,0.0004618405,0.0004366505,0.0001988641,0.0002379985,0.001648806],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.03715299,"threshold_uncertainty_score":0.1964861,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.2513614997087211,"score_gpt":0.2536368033275691,"score_spread":0.002275303618848035,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}