\section{Results}\label{sec:results}
We simulate membership inference attacks on both centralized and federation trained models for the BrainAGE problem. We report results on models trained centrally in \sectionref{subsec:centralized_result} and distributively in \sectionref{subsec:federated_result}.
Conventional deep learning models are trained using gradient descent. Thus, the gradient of parameters w.r.t.\ loss computed from a trained model are likely to be lower for the training set than the unseen set.  We evaluate features derived from gradients, activation, errors, and predictions of the trained model to train the binary classifier  and study their effectiveness in \sectionref{subsec:centralized_result}.
The main task is to identify if a sample belonged to the training set. We report the accuracy of correct identification on a test set  created from the training and the unseen sample sets that were not used to train the attack model but used for training and evaluating the {brain age} models.

\input{sections/results/centralized_training}
\input{sections/results/federated_training}
\input{sections/results/remedy}




