AIセキュリティポータル K Program
Closed-Form Bounds for DP-SGD against Record-level Inference
Share
Abstract
Machine learning models trained with differentially-private (DP) algorithms such as DP-SGD enjoy resilience against a wide range of privacy attacks. Although it is possible to derive bounds for some attacks based solely on an $(\varepsilon,\delta)$-DP guarantee, meaningful bounds require a small enough privacy budget (i.e., injecting a large amount of noise), which results in a large loss in utility. This paper presents a new approach to evaluate the privacy of machine learning models against specific record-level threats, such as membership and attribute inference, without the indirection through DP. We focus on the popular DP-SGD algorithm, and derive simple closed-form bounds. Our proofs model DP-SGD as an information theoretic channel whose inputs are the secrets that an attacker wants to infer (e.g., membership of a data record) and whose outputs are the intermediate model parameters produced by iterative optimization. We obtain bounds for membership inference that match state-of-the-art techniques, whilst being orders of magnitude faster to compute. Additionally, we present a novel data-dependent bound against attribute inference. Our results provide a direct, interpretable, and practical way to evaluate the privacy of trained models against specific inference threats without sacrificing utility.
Deep learning with differential privacy
Martín Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, Li Zhang
Published: 2016
Improving the gaussian mechanism for differential privacy: Analytical calibration and optimal denoising
Borja Balle, Yu-Xiang Wang
Published: 2018
On the Importance of Architecture and Feature Selection in Differentially Private Machine Learning
Wenxuan Bao, Luke A. Bauer, Vincent Bindschaedler
Published: 2022.5.14
Estimates of the proximity of Gaussian measures
SS Barsov, Vladimir V Ul’yanov
Published: 1987
Membership inference attacks from first principles
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, Florian Tramer
Published: 2022
Bayes security: A not so average metric
K. Chatzikokolakis, G. Cherubin, C. Palamidessi, C. Troncoso
Published: 2023
Bayes, not Naïve: Security Bounds on Website Fingerprinting Defenses
Giovanni Cherubin
Published: 2017.2.25
Black-box security: measuring black-box information leakage via machine learning
Giovanni Cherubin
Published: 2019
F-BLEAU: fast black-box leakage estimation
Giovanni Cherubin, Konstantinos Chatzikokolakis, Catuscia Palamidessi
Published: 2019
Characterizations of an empirical influence function for detecting influential cases in regression
R. D. Cook, S. Weisberg
Published: 1980
Elements of information theory
Thomas M Cover
Published: 1999
Connect the dots: Tighter discrete approximations of privacy loss distributions
Vadym Doroshenko, Badih Ghazi, Pritish Kamath, Ravi Kumar, Pasin Manurangsi
Published: 2022
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, Thomas Ristenpart
Published: 2015
Numerical composition of differential privacy
S. Gopi, Y. T. Lee, L. Wutschitz
Published: 2021
The influence curve and its role in robust estimation
Frank R Hampel
Published: 1974
Approximating the kullback leibler divergence between gaussian mixture models
John R Hershey, Peder A Olsen
Published: 2007
Efficient approximation algorithms for point-set diameter in higher dimensions
Mahdi Imanparast, Seyed Naser Hashemi, Ali Mohades
Published: 2019
No free lunch in data privacy
Published: 2011
Membership privacy: A unifying framework for privacy definitions
Li, N., Qardaji, W., Su, D., Wu, Y., Yang, W.
Published: 2013
Optimal membership inference bounds for adaptive composition of sampled gaussian mechanisms
Saeed Mahloujifar, Alexandre Sablayrolles, Graham Cormode, Somesh Jha
Published: 2022
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 2021.11.18
On the foundations of quantitative information flow
Geoffrey Smith
Published: 2009
On constructing minimum spanning trees in k-dimensional spaces and related problems
Andrew Chi-Chih Yao
Published: 1982
Overfitting, robustness, and malicious algorithms: A study of potential causes of privacy risk in machine learning
Samuel Yeom, Irene Giacomelli, Alan Menaged, Matt Fredrikson, Somesh Jha
Published: 2020
Bayesian Estimation of Differential Privacy
Santiago Zanella-Béguelin, Lukas Wutschitz, Shruti Tople, Ahmed Salem, Victor Rühle, Andrew Paverd, Mohammad Naseri, Boris Köpf, Daniel Jones
Published: 2022.6.11
Share