Fixed threshold attack model, in which the attacker leverages correlation data, and baselines only flip SNVs. (A) θ = 1000, baselines only flip SNVs. (B) θ = −250, baselines only mask SNVs.