Class Clown: Data Redaction in Machine Unlearning at Enterprise Scale

12/08/2020
by   Daniel L. Felps, et al.
0

Individuals are gaining more control of their personal data through recent data privacy laws such the General Data Protection Regulation and the California Consumer Privacy Act. One aspect of these laws is the ability to request a business to delete private information, the so called "right to be forgotten" or "right to erasure". These laws have serious financial implications for companies and organizations that train large, highly accurate deep neural networks (DNNs) using these valuable consumer data sets. However, a received redaction request poses complex technical challenges on how to comply with the law while fulfilling core business operations. We introduce a DNN model lifecycle maintenance process that establishes how to handle specific data redaction requests and minimize the need to completely retrain the model. Our process is based upon the membership inference attack as a compliance tool for every point in the training set. These attack models quantify the privacy risk of all training data points and form the basis of follow-on data redaction from an accurate deployed model; excision is implemented through incorrect label assignment within incremental model updates.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/08/2023

Right to be Forgotten in the Era of Large Language Models: Implications, Challenges, and Solutions

The Right to be Forgotten (RTBF) was first established as the result of ...
research
12/02/2019

GDPArrrrr: Using Privacy Laws to Steal Identities

The General Data Protection Regulation (GDPR) has become a touchstone mo...
research
07/26/2020

Anonymizing Machine Learning Models

There is a known tension between the need to analyze personal data to dr...
research
10/06/2022

Exploring the Relationships between Privacy by Design Schemes and Privacy Laws: A Comparative Analysis

Internet of Things (IoT) applications have the potential to derive sensi...
research
07/23/2020

Model Driven Engineering for Data Protection and Privacy: Application and Experience with GDPR

In Europe and indeed worldwide, the General Data Protection Regulation (...
research
10/30/2019

Forgotten @ Scale: A Practical Solution for Implementing the Right To Be Forgotten in Large-Scale Systems

The European General Data Protection Regulation asserts data subjects' r...
research
05/19/2022

An Empirical Evaluation of the Implementation of the California Consumer Privacy Act (CCPA)

On January 1, 2020, California passed the California Consumer Privacy Ac...

Please sign up or login with your details

Forgot password? Click here to reset