Table 4.
Pre- and post-defense accuracy of attack model on CIFAR-100
Attack method
Metric
No. defended
Non-member mask
Member mask
Ml-leaks
Accuracy
0.9134
0.5000
0.5396
Precision
0.9033
0.0000
0.5206
Recall
0.9702
0.0000
0.9999
F1-score
0.9355
–
0.6847
BlindMI
Accuracy
0.8830
0.5010
0.5031
Precision
0.8119
0.5005
0.5039
Recall
0.9969
1.0000
0.4033
F1-score
0.8958
0.6671
0.4480
Attack method
Metric
No. defended
Non-member mask
Member mask
Ml-leaks
Accuracy
0.9134
0.5000
0.5396
Precision
0.9033
0.0000
0.5206
Recall
0.9702
0.0000
0.9999
F1-score
0.9355
–
0.6847
BlindMI
Accuracy
0.8830
0.5010
0.5031
Precision
0.8119
0.5005
0.5039
Recall
0.9969
1.0000
0.4033
F1-score
0.8958
0.6671
0.4480
Source:
Authors’ own data, using the Ml-leaks described by Salem
et al
. and BlindMI described by Hui
et al
.
[ViewLarge]
Close Modal
Close Modal
This Feature Is Available To Subscribers Only
Sign In
or
Create an Account
Close Modal
Close Modal