Data Provenance via Differential Auditing

09/04/2022
by   Xin Mu, et al.
0

Auditing Data Provenance (ADP), i.e., auditing if a certain piece of data has been used to train a machine learning model, is an important problem in data provenance. The feasibility of the task has been demonstrated by existing auditing techniques, e.g., shadow auditing methods, under certain conditions such as the availability of label information and the knowledge of training protocols for the target model. Unfortunately, both of these conditions are often unavailable in real applications. In this paper, we introduce Data Provenance via Differential Auditing (DPDA), a practical framework for auditing data provenance with a different approach based on statistically significant differentials, i.e., after carefully designed transformation, perturbed input data from the target model's training set would result in much more drastic changes in the output than those from the model's non-training set. This framework allows auditors to distinguish training data from non-training ones without the need of training any shadow models with the help of labeled output data. Furthermore, we propose two effective auditing function implementations, an additive one and a multiplicative one. We report evaluations on real-world data sets demonstrating the effectiveness of our proposed auditing technique.

READ FULL TEXT
research
12/13/2018

Training Set Camouflage

We introduce a form of steganography in the domain of machine learning w...
research
06/08/2021

Supervised Machine Learning with Plausible Deniability

We study the question of how well machine learning (ML) models trained o...
research
03/26/2020

Obliviousness Makes Poisoning Adversaries Weaker

Poisoning attacks have emerged as a significant security threat to machi...
research
09/03/2020

A general approach to bridge the reality-gap

Employing machine learning models in the real world requires collecting ...
research
07/02/2020

A Novel DNN Training Framework via Data Sampling and Multi-Task Optimization

Conventional DNN training paradigms typically rely on one training set a...
research
08/18/2023

Training with Product Digital Twins for AutoRetail Checkout

Automating the checkout process is important in smart retail, where user...
research
11/29/2022

Building Resilience to Out-of-Distribution Visual Data via Input Optimization and Model Finetuning

A major challenge in machine learning is resilience to out-of-distributi...

Please sign up or login with your details

Forgot password? Click here to reset