Understanding Disparate Effects of Membership Inference Attacks and their Countermeasures
Understanding Disparate Effects of Membership Inference Attacks and their Countermeasures
复制标题
了解成员推理攻击的不同影响及其对策
DOI:
10.1145/3488932.3501279
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Wang, Wendy Hui
中科院分区:
文献类型:
--
作者:
Zhong, Da;Sun, Haipei;Xu, Jun;Gong, Neil;Wang, Wendy Hui
Machine learning algorithms, when applied to sensitive data, can pose severe threats to privacy. A growing body of prior work has demonstrated that membership inference attack (MIA) can disclose whether specific private data samples are present in the training data to an attacker. However, most existing studies on MIA focus on aggregated privacy leakage for an entire population, while leaving privacy leakage across different demographic subgroups (e.g., females and males) in the population largely unexplored. This raises two important issues: (1) privacy unfairness (i.e., if some subgroups are more vulnerable to MIAs than the others); and (2) defense unfairness (i.e., if the defense mechanisms provide more protection to some particular subgroups than the others).In this paper, we investigate both privacy unfairness and defense fairness.We formalize a new notation of privacy-leakage disparity (PLD), which quantifies the disparate privacy leakage of machine learning models to MIA across different subgroups. In terms of privacy unfairness, our empirical analysis of PLD on real-world datasets shows that privacy unfairness exists. The minority subgroups (i.e., the less represented subgroups) tend to have higher privacy leakage. We analyze how subgroup size and subgroup data distribution impact PLD through the lens of model memorization. In terms of defense unfairness, our empirical evaluation shows the existence of unfairness of three state-of-the-art defenses, namely differential privacy, L2-regularizer, and Dropout, against MIA. However, defense unfairness mitigates privacy unfairness as the minority subgroups receive stronger protection than the others. We analyze how the three defense mechanisms affect subgroup data distribution disparately and thus leads to defense unfairness.
登录
查看更多内容
DOI:
--
发表时间:
2020-06
期刊:
ArXiv
影响因子:
--
作者:
Matthew Jagielski;Jonathan Ullman;Alina Oprea
通讯作者:
Matthew Jagielski;Jonathan Ullman;Alina Oprea
DOI:
10.1609/aaai.v35i11.17193
发表时间:
2020-09
期刊:
ArXiv
影响因子:
--
作者:
Cuong Tran;Ferdinando Fioretto;Pascal Van Hentenryck
通讯作者:
Cuong Tran;Ferdinando Fioretto;Pascal Van Hentenryck
DOI:
10.1007/978-3-662-44851-9_44
发表时间:
2014
期刊:
AJR. American journal of roentgenology
影响因子:
--
作者:
S. Ruggieri;S. Hajian;F. Kamiran;Xiangliang Zhang
通讯作者:
Xiangliang Zhang
DOI:
--
发表时间:
2018
期刊:
Accountability and Transparency
影响因子:
--
作者:
Ekstrand, Michael D.;Joshaghani, Rezvan;Mehrpouyan, Hoda
通讯作者:
Mehrpouyan, Hoda
DOI:
--
发表时间:
2005
期刊:
影响因子:
--
作者:
Dan A. Biddle
通讯作者:
Dan A. Biddle