How Worrying Are Privacy Attacks Against Machine Learning?

Fuente: arXiv
Saved in:
Bibliographic Details
Main Author: Domingo-Ferrer, Josep
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912707281682432
author Domingo-Ferrer, Josep
author_facet Domingo-Ferrer, Josep
contents In several jurisdictions, the regulatory framework on the release and sharing of personal data is being extended to machine learning (ML). The implicit assumption is that disclosing a trained ML model entails a privacy risk for any personal data used in training comparable to directly releasing those data. However, given a trained model, it is necessary to mount a privacy attack to make inferences on the training data. In this concept paper, we examine the main families of privacy attacks against predictive and generative ML, including membership inference attacks (MIAs), property inference attacks, and reconstruction attacks. Our discussion shows that most of these attacks seem less effective in the real world than what a prima face interpretation of the related literature could suggest.
format Preprint
id arxiv_https___arxiv_org_abs_2511_10516
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle How Worrying Are Privacy Attacks Against Machine Learning?
Domingo-Ferrer, Josep
Cryptography and Security
68
K.4.1; C.2.0; I.2.6
In several jurisdictions, the regulatory framework on the release and sharing of personal data is being extended to machine learning (ML). The implicit assumption is that disclosing a trained ML model entails a privacy risk for any personal data used in training comparable to directly releasing those data. However, given a trained model, it is necessary to mount a privacy attack to make inferences on the training data. In this concept paper, we examine the main families of privacy attacks against predictive and generative ML, including membership inference attacks (MIAs), property inference attacks, and reconstruction attacks. Our discussion shows that most of these attacks seem less effective in the real world than what a prima face interpretation of the related literature could suggest.
title How Worrying Are Privacy Attacks Against Machine Learning?
topic Cryptography and Security
68
K.4.1; C.2.0; I.2.6
url https://arxiv.org/abs/2511.10516