Does Label Differential Privacy Prevent Label Inference Attacks?

02/25/2022
by   Ruihan Wu, et al.
0

Label differential privacy (LDP) is a popular framework for training private ML models on datasets with public features and sensitive private labels. Despite its rigorous privacy guarantee, it has been observed that in practice LDP does not preclude label inference attacks (LIAs): Models trained with LDP can be evaluated on the public training features to recover, with high accuracy, the very private labels that it was designed to protect. In this work, we argue that this phenomenon is not paradoxical and that LDP merely limits the advantage of an LIA adversary compared to predicting training labels using the Bayes classifier. At LDP ϵ=0 this advantage is zero, hence the optimal attack is to predict according to the Bayes classifier and is independent of the training labels. Finally, we empirically demonstrate that our result closely captures the behavior of simulated attacks on both synthetic and real world datasets.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/04/2022

Differentially Private Label Protection in Split Learning

Split learning is a distributed training framework that allows multiple ...
research
12/25/2017

Towards Measuring Membership Privacy

Machine learning models are increasingly made available to the masses th...
research
09/22/2022

In Differential Privacy, There is Truth: On Vote Leakage in Ensemble Private Learning

When learning from sensitive data, care must be taken to ensure that tra...
research
06/11/2021

A Shuffling Framework for Local Differential Privacy

ldp deployments are vulnerable to inference attacks as an adversary can ...
research
10/04/2018

Finding Solutions to Generative Adversarial Privacy

We present heuristics for solving the maximin problem induced by the gen...
research
11/01/2016

Variational Bayes In Private Settings (VIPS)

We provide a general framework for privacy-preserving variational Bayes ...
research
10/05/2021

Label differential privacy via clustering

We present new mechanisms for label differential privacy, a relaxation o...

Please sign up or login with your details

Forgot password? Click here to reset