Poster Abstract: Protecting User Data Privacy with Adversarial Perturbations.

Poster Abstract: Protecting User Data Privacy with Adversarial Perturbations.
复制标题

DOI:
10.1145/3412382.3458776
复制
发表时间:
2021-05
期刊:
IPSN : [proceedings]. IPSN (Conference)
影响因子:
--
通讯作者:
Srivastava M
Srivastava M
中科院分区:
其他
文献类型:
--
作者:
Wang Z;Wang B;Srivastava M

文献摘要

相似文献

身体传感器的日益普及使研究人员能够获取丰富的时间序列数据,其中许多与人类健康状况有关。共享此类数据可以促进跨机构合作,创建先进的数据驱动模型来推断人类的健康状况。然而,此类数据通常被视为对隐私敏感,公开共享这些数据可能会引发严重的隐私问题。在这项工作中,我们试图保护临床时间序列数据免受成员推断攻击,同时最大程度地保留数据的效用。我们通过在原始数据中添加难以察觉的噪声来实现这一点。这种噪声被称为对抗性扰动,经过专门训练,可迫使深度学习模型产生推断错误(在我们的案例中,错误预测用户身份)。我们的初步结果表明,与基线相比,我们的解决方案能够更好地保护数据免受成员推断攻击,同时在所有设计的数据质量检查中都取得了成功。
The increased availability of on-body sensors gives researchers access to rich time-series data, many of which are related to human health conditions. Sharing such data can allow cross-institutional collaborations that create advanced data-driven models to make inferences on human well-being. However, such data are usually considered privacy-sensitive, and publicly sharing this data may incur significant privacy concerns. In this work, we seek to protect clinical time-series data against membership inference attacks, while maximally retaining the data utility. We achieve this by adding an imperceptible noise to the raw data. Known as adversarial perturbations, the noise is specially trained to force a deep learning model to make inference mistakes (in our case, mispredicting user identities). Our preliminary results show that our solution can better protect the data from membership inference attacks than the baselines, while succeeding in all the designed data quality checks.