Table 2. MIA result summary of trained attack on MNIST dataset for moderate noise level.
Moderate noise (
) Attack type = trained attack | |||||
---|---|---|---|---|---|
Slice feature/ | Attacker | AUC | Precision | Recall | F1 score |
Slice value | advantage | ||||
Entire dataset | 0.14 | 0.52 | 0.48 | 0.50 | 0.49 |
Class 0 | 0.09 | 0.54 | 0.47 | 0.51 | 0.49 |
Class 1 | 0.24 | 0.53 | 0.47 | 0.50 | 0.48 |
Class 2 | 0.22 | 0.53 | 0.48 | 0.51 | 0.49 |
Class 3 | 0.20 | 0.53 | 0.49 | 0.51 | 0.50 |
Class 4 | 0.16 | 0.53 | 0.48 | 0.51 | 0.49 |
Class 5 | 0.06 | 0.51 | 0.50 | 0.51 | 0.51 |
Class 6 | 0.24 | 0.55 | 0.47 | 0.52 | 0.50 |
Class 7 | 0.05 | 0.52 | 0.49 | 0.51 | 0.50 |
Class 8 | 0.20 | 0.54 | 0.46 | 0.51 | 0.48 |
Class 9 | 0.08 | 0.53 | 0.48 | 0.51 | 0.49 |
Correctly classified | 0.22 | 0.54 | 0.47 | 0.51 | 0.49 |
True | |||||
Correctly classified | 0.06 | 0.52 | 0.49 | 0.50 | 0.49 |
False |