Addressing sub-optimal adversaries in differentially private machine learning

Neural Information Processing Systems 

MI can lead to the disclosure of highly sensitive information about the individual, e.g. that