Fig. 2: Theoretical reconstruction bounds for a worst-case and slightly relaxed adversary.
From: Reconciling privacy and accuracy in AI for medical imaging

From left to right: RadImageNet, HAM10000 and MSD Liver. We see that the mathematical upper bound for a reconstruction risk of a minimally relaxed threat model (orange) is already substantially lower compared with a worst-case setting (purple).