Table 12. Comparison with state-of-the-art techniques.
Defense technique | Model accuracy (%) | Attack performance |
---|---|---|
Randomized response | – | 0.57 |
DP-SGD | – | 0.52 |
MemGuard | 83.2 | 0.66 |
Adversarial regularizations | 78.5 | 0.57 |
SELENA | 79.3 | 0.54 |
DP-BCD | 80 | 0.51 |