English

Privacy Vulnerabilities in Marginals-based Synthetic Data

Cryptography and Security 2025-04-02 v2 Machine Learning

Abstract

When acting as a privacy-enhancing technology, synthetic data generation (SDG) aims to maintain a resemblance to the real data while excluding personally-identifiable information. Many SDG algorithms provide robust differential privacy (DP) guarantees to this end. However, we show that the strongest class of SDG algorithms--those that preserve \textit{marginal probabilities}, or similar statistics, from the underlying data--leak information about individuals that can be recovered more efficiently than previously understood. We demonstrate this by presenting a novel membership inference attack, MAMA-MIA, and evaluate it against three seminal DP SDG algorithms: MST, PrivBayes, and Private-GSD. MAMA-MIA leverages knowledge of which SDG algorithm was used, allowing it to learn information about the hidden data more accurately, and orders-of-magnitude faster, than other leading attacks. We use MAMA-MIA to lend insight into existing SDG vulnerabilities. Our approach went on to win the first SNAKE (SaNitization Algorithm under attacK ... ε\varepsilon) competition.

Keywords

Cite

@article{arxiv.2410.05506,
  title  = {Privacy Vulnerabilities in Marginals-based Synthetic Data},
  author = {Steven Golob and Sikha Pentyala and Anuar Maratkhan and Martine De Cock},
  journal= {arXiv preprint arXiv:2410.05506},
  year   = {2025}
}

Comments

Accepted at 3rd IEEE Conference on Secure and Trustworthy Machine Learning (SaTML) 2025

R2 v1 2026-06-28T19:12:10.078Z