{"id":"W4396243913","doi":"10.1145/3658644.3690194","title":"Evaluations of Machine Learning Privacy Defenses are Misleading","year":2024,"lang":"en","type":"preprint","venue":"","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":14,"is_retracted":false,"has_abstract":true,"ca_institutions":"","funders":"Canadian Institute for Advanced Research; Universitas Brawijaya; Schweizerischer Nationalfonds zur Förderung der Wissenschaftlichen Forschung; National Science Foundation","keywords":"Internet privacy; Computer science; Computer security; Business; Psychology; Artificial intelligence","routes":{"ca_aff":false,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":true},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":["metaresearch"],"consensus_categories":[],"category_scores_codex":[0.03301297,0.001790553,0.001344708,0.00174383,0.001921101,0.004874171,0.003453619,0.00377981,0.006296686],"category_scores_gemma":[0.1578042,0.0007629516,0.001239062,0.001777391,0.006047416,0.009979009,0.006159364,0.009319394,0.001526535],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.004152604,"about_ca_system_score_gemma":0.00249915,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.000418758,"about_ca_topic_score_gemma":0.0006403924,"domain_scores_codex":[0.9338549,0.03759876,0.002117438,0.003845018,0.02046825,0.002115549],"domain_scores_gemma":[0.8457704,0.09603965,0.005760264,0.04363308,0.007431431,0.001365183],"domain_codex":null,"domain_gemma":"evaluation","domain_candidate":"evaluation","domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001582102,0.001025657,0.01030041,0.001738533,0.0004753289,0.0002011705,0.0006282653,0.1430187,0.01004956,0.5423584,0.02911677,0.2595052],"study_design_scores_gemma":[0.0003784042,0.001673758,0.003355701,0.0008436449,0.000202666,0.001139296,0.0005955066,0.4109102,0.03488587,0.5103201,0.03558385,0.0001109479],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1630644,0.009853572,0.7247099,0.02166994,0.0007645556,0.000627298,0.001274414,0.002948053,0.07508785],"genre_scores_gemma":[0.9088246,0.001357924,0.08267672,0.002653334,0.0002648026,0.0003172454,0.0006493298,0.0003319303,0.002924059],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.966987,"threshold_uncertainty_score":0.1745914,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03983493120052315,"score_gpt":0.3299973261049216,"score_spread":0.2901623949043984,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}