We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.LG

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Machine Learning

Title: Disparate Vulnerability to Membership Inference Attacks

Abstract: A membership inference attack (MIA) against a machine-learning model enables an attacker to determine whether a given data record was part of the model's training data or not. In this paper, we provide an in-depth study of the phenomenon of disparate vulnerability against MIAs: unequal success rate of MIAs against different population subgroups. We first establish necessary and sufficient conditions for MIAs to be prevented, both on average and for population subgroups, using a notion of distributional generalization. Second, we derive connections of disparate vulnerability to algorithmic fairness and to differential privacy. We show that fairness can only prevent disparate vulnerability against limited classes of adversaries. Differential privacy bounds disparate vulnerability but can significantly reduce the accuracy of the model. We show that estimating disparate vulnerability to MIAs by na\"ively applying existing attacks can lead to overestimation. We then establish which attacks are suitable for estimating disparate vulnerability, and provide a statistical framework for doing so reliably. We conduct experiments on synthetic and real-world data finding statistically significant evidence of disparate vulnerability in realistic settings. The code is available at this https URL
Comments: To appear in Privacy-Enhancing Technologies Symposium (PETS) 2022. This version has an updated authors list
Subjects: Machine Learning (cs.LG); Cryptography and Security (cs.CR); Computers and Society (cs.CY); Machine Learning (stat.ML)
Cite as: arXiv:1906.00389 [cs.LG]
  (or arXiv:1906.00389v4 [cs.LG] for this version)

Submission history

From: Bogdan Kulynych [view email]
[v1] Sun, 2 Jun 2019 11:37:00 GMT (435kb,D)
[v2] Fri, 24 Jul 2020 12:33:38 GMT (1728kb,D)
[v3] Wed, 15 Sep 2021 14:43:33 GMT (472kb,D)
[v4] Thu, 16 Sep 2021 19:21:39 GMT (472kb,D)

Link back to: arXiv, form interface, contact.