Table 5.

Pre- and post-defense accuracy of attack model on Caltech-UCSD Birds 200

Attack methodMetricNo. defendedNon-member maskMember mask
Ml-leaksAccuracy0.98380.50000.5950
Precision0.96910.00000.5566
Recall1.00000.00001.0000
F1-score0.98430.7152
BlindMIAccuracy0.98010.01010.4983
Precision0.96230.00000.5143
Recall1.00000.00000.2397
F1-score0.98080.3270
Source: Authors’ own data, using the Ml-leaks described by Salem et al. and BlindMI described by Hui et al.

or Create an Account

Close Modal
Close Modal