Support class-based membership inference
abigailgold opened this issue · 1 comments
abigailgold commented
Currently blackbox membership inference attack treats all data in the same manner, training a single attack model for everything.
If true labels are provided, the attack can create separate attack models per class label (which has been shown to improve attack accuracy).