Skip to content
This repository has been archived by the owner on Jan 8, 2023. It is now read-only.

Testing Data for the attack model #11

Open
zliangak opened this issue Mar 11, 2020 · 0 comments
Open

Testing Data for the attack model #11

zliangak opened this issue Mar 11, 2020 · 0 comments

Comments

@zliangak
Copy link

Firstly, thanks for you contribution of mia, which is a very well-structured and concise implementation of the model inference attack.

However, one thing confuses me is that, in your cifar10 example, line 150-152, you include (x_test, y_test) into the dataset for testing the attacker, which is used for training the shadow model. For my perspective, this is inappropriate since the attack model has already seen these data indirectly through the shadow models, which breach the assumption that the testing is unseen before.

In the official implementation https://github.com/csong27/membership-inference, they seem to avoid this by separating one more testing set out.

I don not know whether my understanding is correct.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant