The Fundamental Limits of Least-Privilege Learning
Theresa Stadler, Bogdan Kulynych, Michael Gastpar, Nicolas Papernot, Carmela Troncoso
Abstract
The promise of least-privilege learning -- to find feature representations that are useful for a learning task but prevent inference of any sensitive information unrelated to this task -- is highly appealing. However, so far this concept has only been stated informally. It thus remains an open question whether and how we can achieve this goal. In this work, we provide the first formalisation of the least-privilege principle for machine learning and characterise its feasibility. We prove that there is a fundamental trade-off between a representation's utility for a given task and its leakage beyond the intended task: it is not possible to learn representations that have high utility for the intended task but, at the same time prevent inference of any attribute other than the task label itself. This trade-off holds under realistic assumptions on the data distribution and regardless of the technique used to learn the feature mappings that produce these representations. We empirically validate this result for a wide range of learning techniques, model architectures, and datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 71dec4f4-cfe3-499f-af62-14da3b718806Cited by top-tier papers1
Ask how each one uses itBuilds on7
- TabNet: Attentive Interpretable Tabular LearningSercan Ö. Arik, Tomas PfisterAAAI 2021 · 2,148 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant RepresentationsKaran Ganju, Qi Wang, Wei Yang, Carl A. Gunter et al.CCS 2018 · 574 citations
- Overlearning Reveals Sensitive AttributesCongzheng Song, Vitaly ShmatikovICLR 2020 · 177 citations
- Not All Features Are Equal: Discovering Essential Features for Preserving Prediction PrivacyFatemehsadat Mireshghallah, Mohammadkazem Taram, Ali Jalali, Ahmed Taha Elthakeb et al.WWW 2021 · 59 citations
Related papers
- Learning Robust and Privacy-Preserving Representations via Information TheoryBinghui Zhang, Sayedeh Leila Noorbakhsh, Yun Dong, Yuan Hong et al.AAAI 2025 · 4 citations
- Trade-offs and Guarantees of Adversarial Representation Learning for Information ObfuscationHan Zhao, Jianfeng Chi, Yuan Tian, Geoffrey J. GordonNeurIPS 2020 · 29 citations
- Understanding Fairness and Prediction Error through Subspace Decomposition and Influence AnalysisEnze Shi, Pankaj Bhagwat, Zhixian Yang, Linglong Kong et al.NeurIPS 2025
- Controllable Universal Fair Representation LearningYue Cui, Chen Ma, Kai Zheng, Lei Chen et al.WWW 2023 · 5 citations
- Adversarial Learning of Privacy-Preserving and Task-Oriented RepresentationsTaihong Xiao, Yi-Hsuan Tsai, Kihyuk Sohn, Manmohan Chandraker et al.AAAI 2020 · 87 citations
