Quantifying Membership Privacy via Information Leakage

被引:20
作者
Saeidian, Sara [1 ]
Cervia, Giulia [2 ,3 ]
Oechtering, Tobias J. [1 ]
Skoglund, Mikael [1 ]
机构
[1] KTH Royal Inst Technol, Div Informat Sci & Engn, Sch Elect Engn & Comp Sci, S-10044 Stockholm, Sweden
[2] KTH Royal Inst Technol, Sch Elect Engn & Comp Sci, S-10044 Stockholm, Sweden
[3] Univ Lille, Ctr Digital Syst, IMT Lille Douai, Inst Mines Telecom, F-59000 Lille, France
关键词
Privacy; Differential privacy; Measurement; Training; Machine learning; Data models; Upper bound; Privacy-preserving machine learning; membership inference; maximal leakage; log-concave probability density;
D O I
10.1109/TIFS.2021.3073804
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Machine learning models are known to memorize the unique properties of individual data points in a training set. This memorization capability can be exploited by several types of attacks to infer information about the training data, most notably, membership inference attacks. In this paper, we propose an approach based on information leakage for guaranteeing membership privacy. Specifically, we propose to use a conditional form of the notion of maximal leakage to quantify the information leaking about individual data entries in a dataset, i.e., the entrywise information leakage. We apply our privacy analysis to the Private Aggregation of Teacher Ensembles (PATE) framework for privacy-preserving classification of sensitive data and prove that the entrywise information leakage of its aggregation mechanism is Schur-concave when the injected noise has a log-concave probability density. The Schur-concavity of this leakage implies that increased consensus among teachers in labeling a query reduces its associated privacy cost. Finally, we derive upper bounds on the entrywise information leakage when the aggregation mechanism uses Laplace distributed noise.
引用
收藏
页码:3096 / 3108
页数:13
相关论文
共 50 条
[21]   Tunable Measures for Information Leakage and Applications to Privacy-Utility Tradeoffs [J].
Liao, Jiachun ;
Kosut, Oliver ;
Sankar, Lalitha ;
Calmon, Flavio du Pin .
IEEE TRANSACTIONS ON INFORMATION THEORY, 2019, 65 (12) :8043-8066
[22]   An approach for prevention of privacy breach and information leakage in sensitive data mining [J].
Prakash, M. ;
Singaravel, G. .
COMPUTERS & ELECTRICAL ENGINEERING, 2015, 45 :134-140
[23]   Quantifying Web-Search Privacy [J].
Gervais, Arthur ;
Shokri, Reza ;
Singla, Adish ;
Capkun, Srdjan ;
Lenders, Vincent .
CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, :966-977
[24]   Gotcha! This Model Uses My Code! Evaluating Membership Leakage Risks in Code Models [J].
Yang, Zhou ;
Zhao, Zhipeng ;
Wang, Chenyu ;
Shi, Jieke ;
Kim, Dongsun ;
Han, Donggyun ;
Lo, David .
IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2024, 50 (12) :3290-3306
[25]   Quantifying the Vulnerability of Attributes for Effective Privacy Preservation Using Machine Learning [J].
Majeed, Abdul ;
Hwang, Seong Oun .
IEEE ACCESS, 2023, 11 :4400-4411
[26]   Secure Inference via Deep Learning as a Service without Privacy Leakage [J].
Anh-Tu Tran ;
The-Dung Luong ;
Cong-Chieu Ha ;
Duc-Tho Hoang ;
Thi-Luong Tran .
2021 RIVF INTERNATIONAL CONFERENCE ON COMPUTING AND COMMUNICATION TECHNOLOGIES (RIVF 2021), 2021, :267-272
[27]   MagSpy: Revealing User Privacy Leakage via Magnetometer on Mobile Devices [J].
Fu, Yongjian ;
Yang, Lanqing ;
Pan, Hao ;
Chen, Yi-Chao ;
Xue, Guangtao ;
Ren, Ju .
IEEE TRANSACTIONS ON MOBILE COMPUTING, 2025, 24 (03) :2455-2469
[28]   Preserving Privacy in GANs Against Membership Inference Attack [J].
Shateri, Mohammadhadi ;
Messina, Francisco ;
Labeau, Fabrice ;
Piantanida, Pablo .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 :1728-1743
[29]   Privacy Preserving Smart Meter Streaming Against Information Leakage of Appliance Status [J].
Hong, Yuan ;
Liu, Wen Ming ;
Wang, Lingyu .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2017, 12 (09) :2227-2241
[30]   Context-Aware Local Information Privacy [J].
Jiang, Bo ;
Seif, Mohamed ;
Tandon, Ravi ;
Li, Ming .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 :3694-3708