Reconstruction Attacks on Machine Unlearning: Simple Models are Vulnerable

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Bertran, Martin, Tang, Shuai, Kearns, Michael, Morgenstern, Jamie, Roth, Aaron, Wu, Zhiwei Steven
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914816704118784
author Bertran, Martin
Tang, Shuai
Kearns, Michael
Morgenstern, Jamie
Roth, Aaron
Wu, Zhiwei Steven
author_facet Bertran, Martin
Tang, Shuai
Kearns, Michael
Morgenstern, Jamie
Roth, Aaron
Wu, Zhiwei Steven
contents Machine unlearning is motivated by desire for data autonomy: a person can request to have their data's influence removed from deployed models, and those models should be updated as if they were retrained without the person's data. We show that, counter-intuitively, these updates expose individuals to high-accuracy reconstruction attacks which allow the attacker to recover their data in its entirety, even when the original models are so simple that privacy risk might not otherwise have been a concern. We show how to mount a near-perfect attack on the deleted data point from linear regression models. We then generalize our attack to other loss functions and architectures, and empirically demonstrate the effectiveness of our attacks across a wide range of datasets (capturing both tabular and image data). Our work highlights that privacy risk is significant even for extremely simple model classes when individuals can request deletion of their data from the model.
format Preprint
id arxiv_https___arxiv_org_abs_2405_20272
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Reconstruction Attacks on Machine Unlearning: Simple Models are Vulnerable
Bertran, Martin
Tang, Shuai
Kearns, Michael
Morgenstern, Jamie
Roth, Aaron
Wu, Zhiwei Steven
Machine Learning
Cryptography and Security
Machine unlearning is motivated by desire for data autonomy: a person can request to have their data's influence removed from deployed models, and those models should be updated as if they were retrained without the person's data. We show that, counter-intuitively, these updates expose individuals to high-accuracy reconstruction attacks which allow the attacker to recover their data in its entirety, even when the original models are so simple that privacy risk might not otherwise have been a concern. We show how to mount a near-perfect attack on the deleted data point from linear regression models. We then generalize our attack to other loss functions and architectures, and empirically demonstrate the effectiveness of our attacks across a wide range of datasets (capturing both tabular and image data). Our work highlights that privacy risk is significant even for extremely simple model classes when individuals can request deletion of their data from the model.
title Reconstruction Attacks on Machine Unlearning: Simple Models are Vulnerable
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2405.20272