Prior work introduced a quantitative test for model inversion attack: - train another classifier on a different subset of the data (unseen by any other model at any point) - Attack success accuracy is accuracy of the "comparitor model" on recreations