m-kahla / Label-Only-Model-Inversion-Attacks-via-Boundary-Repulsion

24 stars 3 forks source link

The details about the Evaluation Protocol #4

Open hosytuyen opened 1 year ago

hosytuyen commented 1 year ago

Hi,

Thank you for sharing your amazing work.

I am currently working on your code and curious about the details on the evaluation protocol for BREP-MI, which might not be found in the paper.

May I trouble you about these info:

  1. What is the attacked IDs? It is 0..299 or 300 random IDs from 1000 private IDs. The default in your code is 300 random IDs?
  2. How many reconstructed Images per ID? The default in your code is 1 per ID?

Thank you