EMA: Auditing Data Removal from Trained Models

09/08/2021
by   Yangsibo Huang, et al.
11

Data auditing is a process to verify whether certain data have been removed from a trained model. A recently proposed method (Liu et al. 20) uses Kolmogorov-Smirnov (KS) distance for such data auditing. However, it fails under certain practical conditions. In this paper, we propose a new method called Ensembled Membership Auditing (EMA) for auditing data removal to overcome these limitations. We compare both methods using benchmark datasets (MNIST and SVHN) and Chest X-ray datasets with multi-layer perceptrons (MLP) and convolutional neural networks (CNN). Our experiments show that EMA is robust under various conditions, including the failure cases of the previously proposed method. Our code is available at: https://github.com/Hazelsuko07/EMA.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/05/2016

ImageNet pre-trained models with batch normalization

Convolutional neural networks (CNN) pre-trained on ImageNet are the back...
research
07/16/2022

Certified Neural Network Watermarks with Randomized Smoothing

Watermarking is a commonly used strategy to protect creators' rights to ...
research
01/05/2021

Learning from Synthetic Shadows for Shadow Detection and Removal

Shadow removal is an essential task in computer vision and computer grap...
research
09/01/2023

NeuroSurgeon: A Toolkit for Subnetwork Analysis

Despite recent advances in the field of explainability, much remains unk...
research
10/26/2022

Characterizing Datapoints via Second-Split Forgetting

Researchers investigating example hardness have increasingly focused on ...
research
09/09/2023

Towards Robust Model Watermark via Reducing Parametric Vulnerability

Deep neural networks are valuable assets considering their commercial be...
research
07/15/2020

Learning Visual Context by Comparison

Finding diseases from an X-ray image is an important yet highly challeng...

Please sign up or login with your details

Forgot password? Click here to reset