Not All Features Are Equal: Discovering Essential Features for Preserving Prediction Privacy

Not All Features Are Equal: Discovering Essential Features for Preserving Prediction Privacy
复制标题

DOI:
10.1145/3442381.3449965
复制
发表时间:
2021-04
期刊:
Proceedings of the Web Conference 2021
影响因子:
--
通讯作者:
FatemehSadat Mireshghallah;Mohammadkazem Taram;A. Jalali;Ahmed T. Elthakeb;D. Tullsen;H. Esmaeilzadeh
FatemehSadat Mireshghallah;Mohammadkazem Taram;A. Jalali;Ahmed T. Elthakeb;D. Tullsen;H. Esmaeilzadeh
中科院分区:
其他
文献类型:
--
作者:
FatemehSadat Mireshghallah;Mohammadkazem Taram;A. Jalali;Ahmed T. Elthakeb;D. Tullsen;H. Esmaeilzadeh

文献摘要

相似文献

当从云端接收机器学习服务时,提供商不需要接收所有特征;事实上,目标预测任务只需要一部分特征。识别这个子集是这项工作的关键问题。我们制定这个问题作为一个基于梯度的扰动最大化方法,发现这个子集在输入特征空间中的功能,由供应商使用的预测模型。在确定子集之后,我们的框架Cloak使用通过单独的基于梯度的优化过程发现的效用保持常数值来抑制其余的特征。我们表明,斗篷并不一定需要合作,从服务提供商超出其正常的服务,并可以应用在场景中,我们只有黑盒访问服务提供商的模型。我们从理论上保证Cloak的优化降低了发送的数据和筛选表示之间的互信息(MI)的上限。实验结果表明,Cloak将输入和筛选表示之间的互信息减少了85.01%,而效用仅减少了1.42%。此外,我们表明,隐形衣大大削弱了对手的能力,学习和推断非有益的功能。
When receiving machine learning services from the cloud, the provider does not need to receive all features; in fact, only a subset of the features are necessary for the target prediction task. Discerning this subset is the key problem of this work. We formulate this problem as a gradient-based perturbation maximization method that discovers this subset in the input feature space with respect to the functionality of the prediction model used by the provider. After identifying the subset, our framework, Cloak, suppresses the rest of the features using utility-preserving constant values that are discovered through a separate gradient-based optimization process. We show that Cloak does not necessarily require collaboration from the service provider beyond its normal service, and can be applied in scenarios where we only have black-box access to the service provider’s model. We theoretically guarantee that Cloak’s optimizations reduce the upper bound of the Mutual Information (MI) between the data and the sifted representations that are sent out. Experimental results show that Cloak reduces the mutual information between the input and the sifted representations by 85.01% with only negligible reduction in utility (1.42%). In addition, we show that Cloak greatly diminishes adversaries’ ability to learn and infer non-conducive features.