f8928b073ccbec15d35f2a9d39430bfd-Supplemental-Conference.pdf
–Neural Information Processing Systems
Our experiments in Section 3 and Section 4 were conducted with an adversary who has side informa-684 tion about the target point. Here, we reduce the amount of background knowledge the adversary has685 about the target, and measure how this affects the reconstruction upper bound and attack success.686 We do this in the following set-up: Given a target z, we initialize our reconstruction from uniform687 noise and optimize with the gradient-based reconstruction attack introduced in Section 2 to produce688 ˆz.
Neural Information Processing Systems
May-1-2026, 05:07:49 GMT
- Technology: