InstaHide's Sample Complexity When Mixing Two Private Images

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Huang, Baihe, Song, Zhao, Tao, Runzhou, Yin, Junze, Zhang, Ruizhe, Zhuo, Danyang
Formato: Preprint
Publicado: 2020
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866917582655717376
author Huang, Baihe
Song, Zhao
Tao, Runzhou
Yin, Junze
Zhang, Ruizhe
Zhuo, Danyang
author_facet Huang, Baihe
Song, Zhao
Tao, Runzhou
Yin, Junze
Zhang, Ruizhe
Zhuo, Danyang
contents Training neural networks usually require large numbers of sensitive training data, and how to protect the privacy of training data has thus become a critical topic in deep learning research. InstaHide is a state-of-the-art scheme to protect training data privacy with only minor effects on test accuracy, and its security has become a salient question. In this paper, we systematically study recent attacks on InstaHide and present a unified framework to understand and analyze these attacks. We find that existing attacks either do not have a provable guarantee or can only recover a single private image. On the current InstaHide challenge setup, where each InstaHide image is a mixture of two private images, we present a new algorithm to recover all the private images with a provable guarantee and optimal sample complexity. In addition, we also provide a computational hardness result on retrieving all InstaHide images. Our results demonstrate that InstaHide is not information-theoretically secure but computationally secure in the worst case, even when mixing two private images.
format Preprint
id arxiv_https___arxiv_org_abs_2011_11877
institution arXiv
publishDate 2020
record_format arxiv
spellingShingle InstaHide's Sample Complexity When Mixing Two Private Images
Huang, Baihe
Song, Zhao
Tao, Runzhou
Yin, Junze
Zhang, Ruizhe
Zhuo, Danyang
Machine Learning
Computational Complexity
Cryptography and Security
Data Structures and Algorithms
Training neural networks usually require large numbers of sensitive training data, and how to protect the privacy of training data has thus become a critical topic in deep learning research. InstaHide is a state-of-the-art scheme to protect training data privacy with only minor effects on test accuracy, and its security has become a salient question. In this paper, we systematically study recent attacks on InstaHide and present a unified framework to understand and analyze these attacks. We find that existing attacks either do not have a provable guarantee or can only recover a single private image. On the current InstaHide challenge setup, where each InstaHide image is a mixture of two private images, we present a new algorithm to recover all the private images with a provable guarantee and optimal sample complexity. In addition, we also provide a computational hardness result on retrieving all InstaHide images. Our results demonstrate that InstaHide is not information-theoretically secure but computationally secure in the worst case, even when mixing two private images.
title InstaHide's Sample Complexity When Mixing Two Private Images
topic Machine Learning
Computational Complexity
Cryptography and Security
Data Structures and Algorithms
url https://arxiv.org/abs/2011.11877