Dear authors, thanks for releasing the codes of your excellent membership inference paper! I happened to notice that no data augmentations are used when training target models here. Is this intentional? If so, I think this is encouraging the target model to overfit on the training set, so that it is easier for an attacker to conduct membership attacks. Could you please kindly give some comments on this issue? Thanks in advance.
Dear authors, thanks for releasing the codes of your excellent membership inference paper! I happened to notice that no data augmentations are used when training target models here. Is this intentional? If so, I think this is encouraging the target model to overfit on the training set, so that it is easier for an attacker to conduct membership attacks. Could you please kindly give some comments on this issue? Thanks in advance.