Abstract
In this work, we present preliminary results demonstrating the ability to recover a significant amount of information about secret model inputs given only very limited access to model outputs and the ability evaluate the model on additive perturbations to the input.
Abstract (translated by Google)
URL
http://arxiv.org/abs/1904.05712