In Differential Privacy, There is Truth: on Vote-Histogram Leakage in Ensemble Private Learning
Jiaqi Wang, Roei Schuster, Ilia Shumailov, David Lie, Nicolas Papernot
摘要
When learning from sensitive data, care must be taken to ensure that training algorithms address privacy concerns. The canonical Private Aggregation of Teacher Ensembles, or PATE, computes output labels by aggregating the predictions of a (possibly distributed) collection of teacher models via a voting mechanism. The mechanism adds noise to attain a differential privacy guarantee with respect to the teachers' training data. In this work, we observe that this use of noise, which makes PATE predictions stochastic, enables new forms of leakage of sensitive information. For a given input, our adversary exploits this stochasticity to extract high-fidelity histograms of the votes submitted by the underlying teachers. From these histograms, the adversary can learn sensitive attributes of the input such as race, gender, or age. Although this attack does not directly violate the differential privacy guarantee, it clearly violates privacy norms and expectations, and would not be possible without the noise inserted to obtain differential privacy. In fact, counter-intuitively, the attack to provide stronger differential privacy. We hope this encourages future work to consider privacy holistically rather than treat differential privacy as a panacea.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper3
- Bounded and Unbiased Composite Differential PrivacyKai Zhang, Yanjun Zhang, Ruoxi Sun, Pei-Wei Tsai 等S&P 2024 · 被引用 54 次
- dp-promise: Differentially Private Diffusion Probabilistic Models for Image SynthesisHaichen Wang, Shuchao Pang, Zhigang Lu, Yihang Rao 等USENIX Security 2024 · 被引用 36 次
- Auditing Private PredictionKaran Chadha, Matthew Jagielski, Nicolas Papernot, Christopher A. Choquette-Choo 等ICML 2024 · 被引用 10 次
相关 Paper
- G-PATE: Scalable Differentially Private Data Generator via Private Aggregation of Teacher DiscriminatorsYunhui Long, Boxin Wang, Zhuolin Yang, Bhavya Kailkhura 等NeurIPS 2021 · 被引用 91 次
- SeqPATE: Differentially Private Text Generation via Knowledge DistillationZhiliang Tian, Yingxiu Zhao, Ziyue Huang, Yu-Xiang Wang 等NeurIPS 2022 · 被引用 29 次
- Hot PATE: Private Aggregation of Distributions for Diverse TasksEdith Cohen, Benjamin Cohen-Wang, Xin Lyu, Jelani Nelson 等ICLR 2026 · 被引用 5 次
- DataLens: Scalable Privacy Preserving Training via Gradient Compression and AggregationBoxin Wang, Fan Wu, Yunhui Long, Luka Rimanic 等CCS 2021 · 被引用 45 次
- A Linear Reconstruction Approach for Attribute Inference Attacks against Synthetic DataMeenatchi Sundaram Muthu Selva Annamalai, Andrea Gadotti, Luc RocherUSENIX Security 2024 · 被引用 37 次
