Mitigating Membership Inference in Deep Survival Analyses with Differential Privacy

Mitigating Membership Inference in Deep Survival Analyses with Differential Privacy
复制标题

DOI:
10.1109/ichi57859.2023.00022
复制
发表时间:
2023-06
期刊:
2023 IEEE 11th International Conference on Healthcare Informatics (ICHI)
影响因子:
--
通讯作者:
Liyue Fan;Luca Bonomi
Liyue Fan;Luca Bonomi
中科院分区:
其他
文献类型:
--
作者:
Liyue Fan;Luca Bonomi

文献摘要

相似文献

深度神经网络越来越多地集成到医疗保健应用中,以实现准确的预测分析。共享经过训练的深度模型不仅可以促进合作研究工作中的知识整合,还可以公平地获得计算智能。然而,最近的研究表明,对手可能会利用共享模型来学习目标个体在训练集中的参与情况。在这项工作中,我们调查隐私保护模型共享的生存研究。具体来说,我们提出了三个研究问题。(1)深度生存模型会泄露成员信息吗?(2)在深度生存分析中,差异隐私在防御成员推断方面的有效性如何?(3)差异隐私对深度生存分析是否有其他影响?我们的研究评估了新兴深度生存模型中的成员泄漏,并开发了不同的私人培训程序,以提供严格的隐私保护。实验结果表明,深度生存模型泄漏成员信息,我们的方法有效地降低了成员推理的风险。结果还表明,差分隐私引入了有限的性能损失,并可能提高模型的鲁棒性,在噪声数据的存在下,相比非私有模型。
Deep neural networks have been increasingly integrated in healthcare applications to enable accurate predicative analyses. Sharing trained deep models not only facilitates knowledge integration in collaborative research efforts but also enables equitable access to computational intelligence. However, recent studies have shown that an adversary may leverage a shared model to learn the participation of a target individual in the training set. In this work, we investigate privacy-protecting model sharing for survival studies. Specifically, we pose three research questions. (1) Do deep survival models leak membership information? (2) How effective is differential privacy in defending against membership inference in deep survival analyses? (3) Are there other effects of differential privacy on deep survival analyses? Our study assesses the membership leakage in emerging deep survival models and develops differentially private training procedures to provide rigorous privacy protection. The experimental results show that deep survival models leak membership information and our approach effectively reduces membership inference risks. The results also show that differential privacy introduces a limited performance loss, and may improve the model robustness in the presence of noisy data, compared to non-private models.