Optimal privacy guarantees for a relaxed threat model: Addressing sub-optimal adversaries in differentially private machine learning
Georgios Kaissis, Alexander Ziller, Stefan Kolek, Anneliese Riess, Daniel Rueckert
摘要
Differentially private mechanisms restrict the membership inference capabilities of powerful (optimal) adversaries against machine learning models. Such adversaries are rarely encountered in practice. In this work, we examine a more realistic threat model relaxation, where (sub-optimal) adversaries lack access to the exact model training database, but may possess related or partial data. We then formally characterise and experimentally validate adversarial membership inference capabilities in this setting in terms of hypothesis testing errors. Our work helps users to interpret the privacy properties of sensitive data processing systems under realistic threat model relaxations and choose appropriate noise levels for their use-case.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Attack-Aware Noise Calibration for Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon 等NeurIPS 2024 · 被引用 23 次
- Unifying Re-Identification, Attribute Inference, and Data Reconstruction Risks in Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Jamie Hayes 等NeurIPS 2025 · 被引用 15 次
- Auditing -differential privacy in one runSaeed Mahloujifar, Luca Melis, Kamalika ChaudhuriICML 2025
它引用的顶会 Paper16
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos 等USENIX Security 2019 · 被引用 1,386 次
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song 等S&P 2022 · 被引用 1,049 次
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 被引用 354 次
相关 Paper
- Closed-Form Bounds for DP-SGD against Record-level InferenceGiovanni Cherubin, Boris Köpf, Andrew Paverd, Shruti Tople 等USENIX Security 2024 · 被引用 2 次
- Leveraging Adversarial Examples to Quantify Membership Information LeakageGanesh Del Grosso, Hamid Jalalzai, Georg Pichler, Catuscia Palamidessi 等CVPR 2022 · 被引用 2 次
- Low-Cost High-Power Membership Inference AttacksSajjad Zarifzadeh, Philippe Liu, Reza ShokriICML 2024 · 被引用 92 次
- Gaussian Membership Inference PrivacyTobias Leemann, Martin Pawelczyk, Gjergji KasneciNeurIPS 2023 · 被引用 29 次
- Impact of Dataset Properties on Membership Inference Vulnerability of Deep Transfer LearningMarlon Tobaben, Hibiki Ito, Joonas Jälkö, Yuan He 等NeurIPS 2025 · 被引用 6 次
