Attacks designed to gain access to sensitive information in training data, including membership inference and model inversion. Privacy attacks demonstrate that training data can sometimes be extracted; relevant to privacy representations and security controls.