Privacy-Preserving Model and Preprocessing Verification for Machine Learning

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Li, Wenbiao, Halimi, Anisa, Jiang, Xiaoqian, Vaidya, Jaideep, Ayday, Erman
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910784173375488
author Li, Wenbiao
Halimi, Anisa
Jiang, Xiaoqian
Vaidya, Jaideep
Ayday, Erman
author_facet Li, Wenbiao
Halimi, Anisa
Jiang, Xiaoqian
Vaidya, Jaideep
Ayday, Erman
contents This paper presents a framework for privacy-preserving verification of machine learning models, focusing on models trained on sensitive data. Integrating Local Differential Privacy (LDP) with model explanations from LIME and SHAP, our framework enables robust verification without compromising individual privacy. It addresses two key tasks: binary classification, to verify if a target model was trained correctly by applying the appropriate preprocessing steps, and multi-class classification, to identify specific preprocessing errors. Evaluations on three real-world datasets-Diabetes, Adult, and Student Record-demonstrate that while the ML-based approach is particularly effective in binary tasks, the threshold-based method performs comparably in multi-class tasks. Results indicate that although verification accuracy varies across datasets and noise levels, the framework provides effective detection of preprocessing errors, strong privacy guarantees, and practical applicability for safeguarding sensitive data.
format Preprint
id arxiv_https___arxiv_org_abs_2501_08236
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Privacy-Preserving Model and Preprocessing Verification for Machine Learning
Li, Wenbiao
Halimi, Anisa
Jiang, Xiaoqian
Vaidya, Jaideep
Ayday, Erman
Machine Learning
This paper presents a framework for privacy-preserving verification of machine learning models, focusing on models trained on sensitive data. Integrating Local Differential Privacy (LDP) with model explanations from LIME and SHAP, our framework enables robust verification without compromising individual privacy. It addresses two key tasks: binary classification, to verify if a target model was trained correctly by applying the appropriate preprocessing steps, and multi-class classification, to identify specific preprocessing errors. Evaluations on three real-world datasets-Diabetes, Adult, and Student Record-demonstrate that while the ML-based approach is particularly effective in binary tasks, the threshold-based method performs comparably in multi-class tasks. Results indicate that although verification accuracy varies across datasets and noise levels, the framework provides effective detection of preprocessing errors, strong privacy guarantees, and practical applicability for safeguarding sensitive data.
title Privacy-Preserving Model and Preprocessing Verification for Machine Learning
topic Machine Learning
url https://arxiv.org/abs/2501.08236