Support for blackbox membership inference attack without true labels
abigailgold opened this issue · 0 comments
abigailgold commented
Blackbox membership inference attack currently requires, in addition to the X features or predictions, the true labels of the data y.
In some cases, labeled test data is scarce, limiting the amount of data that can be used to train the attack. If the attack supported using only loss/predictions as input to the attack, it could be applied in cases where labeled data is not sufficient.