Analyzing Inference Privacy Risks Through Gradients in Machine Learning

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Li, Zhuohang, Lowy, Andrew, Liu, Jing, Koike-Akino, Toshiaki, Parsons, Kieran, Malin, Bradley, Wang, Ye
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866910584056840192
author Li, Zhuohang
Lowy, Andrew
Liu, Jing
Koike-Akino, Toshiaki
Parsons, Kieran
Malin, Bradley
Wang, Ye
author_facet Li, Zhuohang
Lowy, Andrew
Liu, Jing
Koike-Akino, Toshiaki
Parsons, Kieran
Malin, Bradley
Wang, Ye
contents In distributed learning settings, models are iteratively updated with shared gradients computed from potentially sensitive user data. While previous work has studied various privacy risks of sharing gradients, our paper aims to provide a systematic approach to analyze private information leakage from gradients. We present a unified game-based framework that encompasses a broad range of attacks including attribute, property, distributional, and user disclosures. We investigate how different uncertainties of the adversary affect their inferential power via extensive experiments on five datasets across various data modalities. Our results demonstrate the inefficacy of solely relying on data aggregation to achieve privacy against inference attacks in distributed learning. We further evaluate five types of defenses, namely, gradient pruning, signed gradient descent, adversarial perturbations, variational information bottleneck, and differential privacy, under both static and adaptive adversary settings. We provide an information-theoretic view for analyzing the effectiveness of these defenses against inference from gradients. Finally, we introduce a method for auditing attribute inference privacy, improving the empirical estimation of worst-case privacy through crafting adversarial canary records.
format Preprint
id arxiv_https___arxiv_org_abs_2408_16913
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Analyzing Inference Privacy Risks Through Gradients in Machine Learning
Li, Zhuohang
Lowy, Andrew
Liu, Jing
Koike-Akino, Toshiaki
Parsons, Kieran
Malin, Bradley
Wang, Ye
Machine Learning
Artificial Intelligence
Cryptography and Security
In distributed learning settings, models are iteratively updated with shared gradients computed from potentially sensitive user data. While previous work has studied various privacy risks of sharing gradients, our paper aims to provide a systematic approach to analyze private information leakage from gradients. We present a unified game-based framework that encompasses a broad range of attacks including attribute, property, distributional, and user disclosures. We investigate how different uncertainties of the adversary affect their inferential power via extensive experiments on five datasets across various data modalities. Our results demonstrate the inefficacy of solely relying on data aggregation to achieve privacy against inference attacks in distributed learning. We further evaluate five types of defenses, namely, gradient pruning, signed gradient descent, adversarial perturbations, variational information bottleneck, and differential privacy, under both static and adaptive adversary settings. We provide an information-theoretic view for analyzing the effectiveness of these defenses against inference from gradients. Finally, we introduce a method for auditing attribute inference privacy, improving the empirical estimation of worst-case privacy through crafting adversarial canary records.
title Analyzing Inference Privacy Risks Through Gradients in Machine Learning
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2408.16913