Formalizing and Estimating Distribution Inference Risks

نویسندگان

چکیده

Distribution inference, sometimes called property infers statistical properties about a training set from access to model trained on that data. inference attacks can pose serious risks when models are private data, but difficult distinguish the intrinsic purpose of machine learning—namely, produce capture distribution. Motivated by Yeom et al.’s membership framework, we propose formal definition distribution general enough describe broad class distinguishing between possible distributions. We show how our captures previous ratio-based as well new kinds attack including revealing average node degree or clustering coefficient graphs. To understand risks, introduce metric quantifies observed leakage relating it would occur if samples were provided directly adversary. report series experiments across range different distributions using both novel black-box and improved versions state-of-the-art white-box attacks. Our results inexpensive often effective expensive meta-classifier attacks, there surprising asymmetries in effectiveness

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Formalizing and extending C type inference

The current release of C (version 2.0) introduces a number of new features intended to increase the expressivity of the language. The most significant is the addition of generics; classes, interfaces, delegates and methods can all be parameterized on types. To make using generic methods easier, C allows the programmer to drop the type arguments in method invocations, and the compiler implements...

متن کامل

Identifying and Estimating Risks

The estimation of risk is concerned with collection information on: (1) The nature and extent of the source; (2) The chain of events, pathways and processes that connect the cause to the effects; and (3) The relationship between the characteristics of the impact (dose) and the types of response (effects). Although response and effects are often equated or used synonymously, the World Health Org...

متن کامل

Risks in estimating risk.

The paper by Vikhireva and colleagues is a timely reminder that one size does not fit all when estimating the risk of cardiovascular death. The authors examined the performance of the European Society of Cardiology (ESC) cardiovascular disease (CVD) risk estimation system SCORE in the Czech Republic, Poland, Lithuania, and Russia, using data from the mid 1980s (MONICA) and early 2000s (HAPIEE)....

متن کامل

Estimating the Radiation-Induced Cancer Risks in Pediatric Computed Tomography

Introduction One of the central questions in radiological protection is the magnitude of the risks from low doses of radiation, related to the justification and optimization of the diagnostic medical exposures. Therefore, the aim of this study was to estimate the cancer incidence and mortality risks in children of different ages, sizes, and ethnicities undergoing computed tomography examination...

متن کامل

Distribution and Inference

We believe that the information encoded in distributional vectors is a lossy projection of an underlying inferential structure. This raises two questions: What’s projected and what’s lost? Let’s start with the inferential picture (abduction) and derive the distributional picture, and then we can see to what extent we can drive it backwards. In the Interpretation as Abduction framework (Hobbs et...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Proceedings on Privacy Enhancing Technologies

سال: 2022

ISSN: ['2299-0984']

DOI: https://doi.org/10.56553/popets-2022-0121