In this paper, we aim to understand the generalization properties of generative adversarial networks (GANs) from a new perspective of privacy protection. /XObject << We propose a new framework for estimating generative models via an adversarial process, in which we simultaneously train two models: a generative model G that captures the data distribution, and a discriminative model D that estimates the probability that a sample came from the training data rather than G. 