This actually might have interesting connections to ideas from differential privacy.
Maybe the work is derivative of a particular training image if we can easily predict the presence or absence of that training image given only the trained model?
Maybe the work is derivative of a particular training image if we can easily predict the presence or absence of that training image given only the trained model?