How much does a given trained model leak about each individual data record in its training set? membership inference attacks are used as an auditing tool to quantify the private information that a model leaks about the individual data points in its training set. →