Provable Privacy Attacks on Trained Shallow Neural Networks
Fuente:
arXiv
Salvato in:
| Autori principali: | , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866912225035288576 |
|---|---|
| author | Smorodinsky, Guy Vardi, Gal Safran, Itay |
| author_facet | Smorodinsky, Guy Vardi, Gal Safran, Itay |
| contents | We study what provable privacy attacks can be shown on trained, 2-layer ReLU neural networks. We explore two types of attacks; data reconstruction attacks, and membership inference attacks. We prove that theoretical results on the implicit bias of 2-layer neural networks can be used to provably reconstruct a set of which at least a constant fraction are training points in a univariate setting, and can also be used to identify with high probability whether a given point was used in the training set in a high dimensional setting. To the best of our knowledge, our work is the first to show provable vulnerabilities in this implicit-bias-driven setting. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2410_07632 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Provable Privacy Attacks on Trained Shallow Neural Networks Smorodinsky, Guy Vardi, Gal Safran, Itay Machine Learning Cryptography and Security We study what provable privacy attacks can be shown on trained, 2-layer ReLU neural networks. We explore two types of attacks; data reconstruction attacks, and membership inference attacks. We prove that theoretical results on the implicit bias of 2-layer neural networks can be used to provably reconstruct a set of which at least a constant fraction are training points in a univariate setting, and can also be used to identify with high probability whether a given point was used in the training set in a high dimensional setting. To the best of our knowledge, our work is the first to show provable vulnerabilities in this implicit-bias-driven setting. |
| title | Provable Privacy Attacks on Trained Shallow Neural Networks |
| topic | Machine Learning Cryptography and Security |
| url | https://arxiv.org/abs/2410.07632 |