[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118755-en":3,"doc-seo-118755-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118755,1099513958762,"Logic","https://ap-avatar.wpscdn.com/avatar/1000023916a998db790?x-image-process=image/resize,m_fixed,w_180,h_180&k=1784791008015729253",8,"Research & Report","SoK - Let the Privacy Games Begin! - A Unified Treatment of Data Inference Privacy in Machine Learning","Machine learning models deployed in production can enable adversaries to infer sensitive information about training data. The literature studies many inference risks, from membership inference to reconstruction attacks, and some works adopt a game-based style inspired by probabilistic experiments in cryptography. Prior presentations often differ subtly in adversary capabilities and objectives, making results hard to compare and combine. This paper introduces a game-based framework that systematizes privacy inference risks. It unifies risk definitions, proves formal relationships, and reveals previously unknown connections, enabling rigorous composition and clearer understanding of inference privacy.","SoK: Let the Privacy Games Begin! A Uniﬁed Treatment of Data Inference Privacy in  \nMachine Learning  \narXiv :2212 . 10986v2 [ cs .LG] 20 Apr 2023  \nAhmed Salem􀀃z , Giovanni Cherubin􀀃 , David Evansy , Boris Kpf􀀃 Andrew Paverd􀀃 , Anshuman Suriy , Shruti Tople􀀃 , Santiago Zanella-Bguelin􀀃z  \n􀀃 Microsoft  \nft-salem.ahmed, giovanni.cherubin, boris.koepf, andrew.paverd, shruti.tople, [santiago](santiagog@microsoft.com)[g](santiagog@microsoft.com)[@microsoft.com](santiagog@microsoft.com)  \ny University of Virginia  \nfevans, [as9rw](as9rwg@virginia.edu)[g](as9rwg@virginia.edu)[@virginia.edu](as9rwg@virginia.edu)  \nAbstract—Deploying machine learning models in production may allow adversaries to infer sensitive information about training data. There is a vast literature analyzing different types of inference risks, ranging from membership inference to reconstruction attacks. Inspired by the success of games (i.e. probabilistic experiments) to study security properties in cryptography, some authors describe privacy inference risks in machine learning using a similar game-based style. However, adversary capabilities and goals are often stated in subtly different ways from one presentation to the other, which makes it hard to relate and compose results. In this paper, we present a game-based framework to systematize the body of knowledge on privacy inference risks in machine learning. We use this framework to (1) provide a unifying structure for deﬁnitions of inference risks, (2) formally establish known relations among deﬁnitions, and (3) to uncover hitherto unknown relations that would have been difﬁcult to spot otherwise.  \nIndex Terms—privacy, machine learning, differential privacy, membership inference, attribute inference, property inference  \nI. INTRODUCTION  \nSince the pioneering studies of attribute inference [22, 69] and membership inference [37, 56], research on the inference risks of deploying machine learning (ML) models has bloomed. There is a growing interest in understanding and mitigating the leakage of information about training data under various threat models that capture different adversarial capabilities (e.g., observing model outputs, model parameters, or transcripts of iterative optimization methods) and goals (e.g., membership inference [56], attribute inference [22, 69], property inference [23, 42, 58, 74], and data reconstruction [4, 11]) . An emerging trend in the literature is to capture threat models using privacy games. This originates from the seminal work of Wu et al. [69] on formalizing attribute inference. A privacy game is a probabilistic experiment where an adversary interacts with a challenger. The challenger drives the experiment, invoking the adversary to provide them with information and to allow them to make certain choices, possibly while interacting with oracles controlled by the challenger. The adversary eventually produces a guess for a conﬁdential value.  \nz Corresponding author  \nThis experiment deﬁnes a probability space where the success of the adversary can be measured in terms of the probability of their guess being correct.  \nThe use of games for privacy in ML is inspired by the wellestablished use of games to deﬁne and reason about security properties in cryptography. Cryptographic games are used to standardize and compare security deﬁnitions [25, 57], and to structure [6] and even mechanize proofs of security [5, 9] . In comparison, the use of privacy games in the ML literature is still in its infancy:  \n(1) there are no well-established standards for game-based deﬁnitions,  \n(2) relationships between different privacy games have only been partially explored, and  \n(3) games are rarely used as an integral part of proofs, despite being especially convenient for this task.  \nThis has resulted in many game variants in the literature that attempt to formalize the same adversary goal but have subtle yet important differences. This fragmentation leads to confusion and hinders progress—for ","cbCais7KjwH6Bgxq","https://ap.wps.com/l/cbCais7KjwH6Bgxq","pdf",631512,1,20,"English","en",105,"# Introduction\n## Privacy inference risks and privacy games\n## Framework overview and contributions\n# Game-based framework (inferred)\n## Anatomy of game-based privacy definitions\n## Unified representation of fundamental risks\n# Relations among risks (inferred)\n## Formal relationships and reduction/separation notions\n## Security implications under threat models","[{\"question\":\"Which privacy risks are represented and connected as games in the paper?\",\"answer\":\"The framework represents five fundamental risks as games: membership inference, attribute inference, property inference, differential privacy distinguishability, and data reconstruction, and then proves rigorous relations among them.\"}]","SoK - Let the Privacy Games Begin! - A Unified Treatment of Data Inference Privacy in Machine Learning | PDF",1785720069,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"sok-let-the-privacy-games-begin-a-unified-treatment-of-data-inference-privacy-in-machine-learning","",{"@graph":36,"@context":77},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/sok-let-the-privacy-games-begin-a-unified-treatment-of-data-inference-privacy-in-machine-learning/118755/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"Which privacy risks are represented and connected as games in the paper?","Question",{"text":75,"@type":76},"The framework represents five fundamental risks as games: membership inference, attribute inference, property inference, differential privacy distinguishability, and data reconstruction, and then proves rigorous relations among them.","Answer","https://schema.org",{"og:url":52,"og:type":79,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":81,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":84},[85,89,93,97,102,106,111,114,118,121,125],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":29,"slug":105},6,"Technology","technology",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":112,"slug":113},30,"research-report",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":21,"slug":117},9,"Religion & Spirituality","religion-spirituality",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":119,"show_sort_weight":21,"slug":120},"World Cup","world-cup",{"id":122,"doc_module":4,"doc_module_name":46,"category_name":123,"show_sort_weight":122,"slug":124},10,"Lifestyle","lifestyle",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":98,"slug":128},19,"General","general"]