Saved in:
Bibliographic Details
Main Authors: Liu, Sheng, Wang, Zihan, Chen, Yuxiao, Lei, Qi
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2402.09478
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909547609718784
author Liu, Sheng
Wang, Zihan
Chen, Yuxiao
Lei, Qi
author_facet Liu, Sheng
Wang, Zihan
Chen, Yuxiao
Lei, Qi
contents Reconstruction attacks and defenses are essential in understanding the data leakage problem in machine learning. However, prior work has centered around empirical observations of gradient inversion attacks, lacks theoretical grounding, and cannot disentangle the usefulness of defending methods from the computational limitation of attacking methods. In this work, we propose to view the problem as an inverse problem, enabling us to theoretically and systematically evaluate the data reconstruction attack. On various defense methods, we derived the algorithmic upper bound and the matching (in feature dimension and architecture dimension) information-theoretical lower bound on the reconstruction error for two-layer neural networks. To complement the theoretical results and investigate the utility-privacy trade-off, we defined a natural evaluation metric of the defense methods with similar utility loss among the strongest attacks. We further propose a strong reconstruction attack that helps update some previous understanding of the strength of defense methods under our proposed evaluation metric.
format Preprint
id arxiv_https___arxiv_org_abs_2402_09478
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Data Reconstruction Attacks and Defenses: A Systematic Evaluation
Liu, Sheng
Wang, Zihan
Chen, Yuxiao
Lei, Qi
Cryptography and Security
Machine Learning
Reconstruction attacks and defenses are essential in understanding the data leakage problem in machine learning. However, prior work has centered around empirical observations of gradient inversion attacks, lacks theoretical grounding, and cannot disentangle the usefulness of defending methods from the computational limitation of attacking methods. In this work, we propose to view the problem as an inverse problem, enabling us to theoretically and systematically evaluate the data reconstruction attack. On various defense methods, we derived the algorithmic upper bound and the matching (in feature dimension and architecture dimension) information-theoretical lower bound on the reconstruction error for two-layer neural networks. To complement the theoretical results and investigate the utility-privacy trade-off, we defined a natural evaluation metric of the defense methods with similar utility loss among the strongest attacks. We further propose a strong reconstruction attack that helps update some previous understanding of the strength of defense methods under our proposed evaluation metric.
title Data Reconstruction Attacks and Defenses: A Systematic Evaluation
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2402.09478