most citedExtracting Training Data from Diffusion Models

100 citations · 161 across the 6 of their papers we have counts for

collaborators

6 papers

cs.LG20239 cited

Privacy Auditing with One (1) Training Run

Thomas Steinke, Milad Nasr, Matthew Jagielski

We propose a scheme for auditing differentially private machine learning systems with a single training run. This exploits the parallelism of being able to add or remove multiple t…

cs.CR20236 cited

Students Parrot Their Teachers: Membership Inference on Model Distillation

Matthew Jagielski, Milad Nasr, Christopher Choquette-Choo +2

Model distillation is frequently proposed as a technique to reduce the privacy leakage of machine learning. These empirical privacy defenses rely on the intuition that distilled ``…

cs.LG20232 cited

Why Is Public Pretraining Necessary for Private Model Training?

Arun Ganesh, Mahdi Haghifam, Milad Nasr +5

In the privacy-utility tradeoff of a model trained on benchmark language and vision tasks, remarkable improvements have been widely reported with the use of pretraining on publicly…

cs.LG202314 cited

Tight Auditing of Differentially Private Machine Learning

Milad Nasr, Jamie Hayes, Thomas Steinke +5

Auditing mechanisms for differential privacy use probabilistic means to empirically estimate the privacy level of an algorithm. For private machine learning, existing auditing mech…

cs.CR2023100 cited

Extracting Training Data from Diffusion Models

Nicholas Carlini, Jamie Hayes, Milad Nasr +6

Image diffusion models such as DALL-E 2, Imagen, and Stable Diffusion have attracted significant attention due to their ability to generate high-quality synthetic images. In this w…

cs.CR202130 cited

Membership Inference Attacks From First Principles

Nicholas Carlini, Steve Chien, Milad Nasr +3

A membership inference attack allows an adversary to query a trained machine learning model to predict whether or not a particular example was contained in the model's training dat…