Effects of Differential Privacy and Data Skewness on Membership Inference Vulnerability | IEEE Conference Publication | IEEE Xplore

Effects of Differential Privacy and Data Skewness on Membership Inference Vulnerability


Abstract:

Membership inference attacks seek to infer the membership of individual training instances of a privately trained model. This paper presents a membership privacy analysis...Show More

Abstract:

Membership inference attacks seek to infer the membership of individual training instances of a privately trained model. This paper presents a membership privacy analysis and evaluation system, MPLens, with three unique contributions. First, through MPLens, we demonstrate how membership inference attack methods can be leveraged in adversarial ML. Second, we highlight with MPLens how the vulnerability of pre-trained models under membership inference attack is not uniform across all classes, particularly when the training data is skewed. We show that risk from membership inference attacks is routinely increased when models use skewed training data. Finally, we investigate the effectiveness of differential privacy as a mitigation technique against membership inference attacks. We discuss the trade-offs of implementing such a mitigation strategy with respect to the model complexity, the learning task complexity, the dataset complexity and the privacy parameter settings.
Date of Conference: 12-14 December 2019
Date Added to IEEE Xplore: 27 February 2020
ISBN Information:
Conference Location: Los Angeles, CA, USA

Contact IEEE to Subscribe

References

References is not available for this document.