Why Does Differential Privacy with Large Epsilon Defend Against Practical Membership Inference Attacks?

Open in new window