返回
Bounding information leakage in machine learning
DOI:10.1016/j.neucom.2023.02.058.png)
摘要
En 中文
Recently, it has been shown that Machine Learning models can leak sensitive information about their training data. This information leakage is exposed through membership and attribute inference attacks. Although many attack strategies have been proposed, little effort has been made to formalize these problems. We present a novel formalism, generalizing membership and attribute inference attack setups previously studied in the literature and connecting them to memorization and generalization. First, we derive a universal bound on the success rate of inference attacks and connect it to the generalization gap of the target model. Second, we study the question of how much sensitive information is stored by the algorithm about its training set and we derive bounds on the mutual information between the sensitive attributes and model parameters. Experimentally, we illustrate the potential of our approach by applying it to both synthetic data and classification tasks on natural images. Finally, we apply our formalism to different attribute inference strategies, with which an adversary is able to recover the identity of writers in the PenDigits dataset.
Keyword:
Membership inference
Privacy
Attacks in machine learning
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
6.5
论文数:
2.5W
被引数:
6.5W
机构
引用论文
Current controlled voltage source inverter using Hysteresis controller and PI controller采用滞环控制器和PI控制器的电流控制电压源逆变器
Impaired Thymic Selection and Abnormal Antigen-Specific T Cell Responses in Foxn1Δ/Δ Mutant Mice
PLoS ONE
IF0

