{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/evaluations-of-machine-learning-privacy","title":"Evaluations of Machine Learning Privacy Defenses are Misleading","arxiv_id":"2404.17399","date":"2024-04-26","proceeding":null,"authors":["Michael Aerni","Jie Zhang","Florian Tramèr"],"abstract":"Empirical defenses for machine learning privacy forgo the provable guarantees of differential privacy in the hope of achieving higher utility while resisting realistic adversaries. We identify severe pitfalls in existing empirical privacy evaluations (based on membership inference attacks) that result in misleading conclusions. In particular, we show that prior evaluations fail to characterize the privacy leakage of the most vulnerable samples, use weak attacks, and avoid comparisons with practical differential privacy baselines. In 5 case studies of empirical privacy defenses, we find that prior evaluations underestimate privacy leakage by an order of magnitude. Under our stronger evaluation, none of the empirical defenses we study are competitive with a properly tuned, high-utility DP-SGD baseline (with vacuous provable guarantees).","url_abs":"https://arxiv.org/abs/2404.17399v2","url_pdf":"https://arxiv.org/pdf/2404.17399v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"evaluations-of-machine-learning-privacy","repo_url":"https://github.com/ethz-spylab/misleading-privacy-evals","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"evaluations-of-machine-learning-privacy","repo_url":"https://github.com/zj-jayzhang/one_round_auditing","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2404.17399","atlas_url":"https://app.syntology.ai/?focus=2404.17399","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2404.17399"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/zj-jayzhang/one_round_auditing","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ethz-spylab/misleading-privacy-evals","reach":{"status":"ok"}}],"summary":{"ran":4,"unverified":1},"by_repo_kind":{"official":{"samples":5,"ran":4,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":5,"samples":[{"code_sha256_prefix":"ee480145a167d1be","entry":"create_ema","repo":"ethz-spylab/misleading-privacy-evals","repo_kind":"official","path":"src/dpsgd_utils.py","file_url":"https://github.com/ethz-spylab/misleading-privacy-evals/blob/HEAD/src/dpsgd_utils.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"ee480145a167d1be"}},{"code_sha256_prefix":"7aea452f400715f2","entry":"get_setting_seed","repo":"ethz-spylab/misleading-privacy-evals","repo_kind":"official","path":"src/base.py","file_url":"https://github.com/ethz-spylab/misleading-privacy-evals/blob/HEAD/src/base.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"7aea452f400715f2"}},{"code_sha256_prefix":"be784f49dfc61120","entry":"hinge_score","repo":"ethz-spylab/misleading-privacy-evals","repo_kind":"official","path":"src/attack_util.py","file_url":"https://github.com/ethz-spylab/misleading-privacy-evals/blob/HEAD/src/attack_util.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"be784f49dfc61120"}},{"code_sha256_prefix":"7888175fabe24762","entry":"lira_attack_loo","repo":"ethz-spylab/misleading-privacy-evals","repo_kind":"official","path":"src/attack_util.py","file_url":"https://github.com/ethz-spylab/misleading-privacy-evals/blob/HEAD/src/attack_util.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"7888175fabe24762"}},{"code_sha256_prefix":"c5ae76274695edf6","entry":"lira_attack","repo":"ethz-spylab/misleading-privacy-evals","repo_kind":"official","path":"src/attack_util.py","file_url":"https://github.com/ethz-spylab/misleading-privacy-evals/blob/HEAD/src/attack_util.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"c5ae76274695edf6"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}