PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining
Cryptography and Security
2024-10-29 v2 Machine Learning
Abstract
We present PANORAMIA, a privacy leakage measurement framework for machine learning models that relies on membership inference attacks using generated data as non-members. By relying on generated non-member data, PANORAMIA eliminates the common dependency of privacy measurement tools on in-distribution non-member data. As a result, PANORAMIA does not modify the model, training data, or training process, and only requires access to a subset of the training data. We evaluate PANORAMIA on ML models for image and tabular data classification, as well as on large-scale language models.
Keywords
Cite
@article{arxiv.2402.09477,
title = {PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining},
author = {Mishaal Kazmi and Hadrien Lautraite and Alireza Akbari and Qiaoyue Tang and Mauricio Soroco and Tao Wang and Sébastien Gambs and Mathias Lécuyer},
journal= {arXiv preprint arXiv:2402.09477},
year = {2024}
}
Comments
36 pages