Table 4.

Pre- and post-defense accuracy of attack model on CIFAR-100

Attack methodMetricNo. defendedNon-member maskMember mask
Ml-leaksAccuracy0.91340.50000.5396
Precision0.90330.00000.5206
Recall0.97020.00000.9999
F1-score0.93550.6847
BlindMIAccuracy0.88300.50100.5031
Precision0.81190.50050.5039
Recall0.99691.00000.4033
F1-score0.89580.66710.4480
Source: Authors’ own data, using the Ml-leaks described by Salem et al. and BlindMI described by Hui et al.

or Create an Account

Close Modal
Close Modal