Hi! hyhmia. It turns out defense you mentioned like MemGuard split data differently like your paper(e.g. in CH-MNIST dataset, target dataset is whole dataset in your paper while in MemGuard, they used only 2000 data as the targer dataset), if it's possible, can you help me find out how you test BlindMI on CH-MNIST dataset as an example? Thank you so much!
Hi! hyhmia. It turns out defense you mentioned like MemGuard split data differently like your paper(e.g. in CH-MNIST dataset, target dataset is whole dataset in your paper while in MemGuard, they used only 2000 data as the targer dataset), if it's possible, can you help me find out how you test BlindMI on CH-MNIST dataset as an example? Thank you so much!