Robust Transparency Against Model Inversion Attacks.

Robust Transparency Against Model Inversion Attacks.
复制标题

针对模型反转攻击的强大透明度

DOI:
10.1109/tdsc.2020.3019508
复制
发表时间:
2021-09
影响因子:
7.3
通讯作者:
Zhou Y
Zhou Y
中科院分区:
计算机科学2区
文献类型:
--
作者:
Alufaisan Y;Kantarcioglu M;Zhou Y

文献摘要

参考文献

相似文献

透明度已成为机器学习(ML)应用程序的关键需求。设计透明的ML模型有助于增加信任,确保问责制,并审查公平性。一些组织可能会选择不透明,以保护个人隐私。因此,对同时考虑隐私和安全风险的透明度模型的需求很大。这种透明模型可以激励组织通过使最终用户能够理解基于ML的决策过程来提高其可信度。差分隐私(DP)提供了在保护个人隐私的同时公开信息的重要技术。然而,已经证明,DP本身无法防止针对公开的ML模型的某些类型的隐私攻击。具有较低安全性值的DP可以提供较高的隐私保证,但可能导致ML模型在准确性方面明显较弱。另一方面,设置过高的隐私值可能会导致成功的隐私攻击。这就提出了一个问题,我们是否可以在保护隐私的同时公开准确的透明ML模型。在本文中,我们介绍了一种新的技术,补充DP,以确保模型的透明度和准确性,同时对模型反演攻击具有鲁棒性。我们表明,将所提出的技术与DP相结合,可以提供高度透明和准确的ML模型,同时保护隐私免受模型反转攻击。
Transparency has become a critical need in machine learning (ML) applications. Designing transparent ML models helps increase trust, ensure accountability, and scrutinize fairness. Some organizations may opt-out of transparency to protect individuals’ privacy. Therefore, there is a great demand for transparency models that consider both privacy and security risks. Such transparency models can motivate organizations to improve their credibility by making the ML-based decision-making process comprehensible to end-users. Differential privacy (DP) provides an important technique to disclose information while protecting individual privacy. However, it has been shown that DP alone cannot prevent certain types of privacy attacks against disclosed ML models. DP with low ϵ values can provide high privacy guarantees, but may result in significantly weaker ML models in terms of accuracy. On the other hand, setting ϵ value too high may lead to successful privacy attacks. This raises the question whether we can disclose accurate transparent ML models while preserving privacy. In this paper we introduce a novel technique that complements DP to ensure model transparency and accuracy while being robust against model inversion attacks. We show that combining the proposed technique with DP provide highly transparent and accurate ML models while preserving privacy against model inversion attacks.
DOI: 10.14778/2350229.2350253
发表时间: 2012-07-01
影响因子: 2.5
作者:
Zhang, Jun;Zhang, Zhenjie;Winslett, Marianne
通讯作者: Winslett, Marianne
DOI: 10.1214/15-aoas848
发表时间: 2015-09-01
影响因子: 1.8
作者:
Letham, Benjamin;Rudin, Cynthia;Madigan, David
通讯作者: Madigan, David