MNIST is too simple to make a compelling paper on its own. Model inversion attack works quite well because images are so simple. We need to use a more "real-world" dataset to present a compelling narrative.
Possible datasets:
- CIFAR10/100
- SVHN (driverless cars are leaking our house information!)
- COCO (can we make out human faces?)
Apply:
- nopeek
- DP
- network architecture experiments