f8928b073ccbec15d35f2a9d39430bfd-Supplemental-Conference.pdf

Neural Information Processing Systems 

Our experiments in Section 3 and Section 4 were conducted with an adversary who has side informa-684 tion about the target point. Here, we reduce the amount of background knowledge the adversary has685 about the target, and measure how this affects the reconstruction upper bound and attack success.686 We do this in the following set-up: Given a target z, we initialize our reconstruction from uniform687 noise and optimize with the gradient-based reconstruction attack introduced in Section 2 to produce688 ˆz.

Similar Docs  Excel Report  more

TitleSimilaritySource
None found