Membership Inference Attacks and Generalization: A Causal Perspective

09/18/2022
by   Teodora Baluta, et al.
0

Membership inference (MI) attacks highlight a privacy weakness in present stochastic training methods for neural networks. It is not well understood, however, why they arise. Are they a natural consequence of imperfect generalization only? Which underlying causes should we address during training to mitigate these attacks? Towards answering such questions, we propose the first approach to explain MI attacks and their connection to generalization based on principled causal reasoning. We offer causal graphs that quantitatively explain the observed MI attack performance achieved for 6 attack variants. We refute several prior non-quantitative hypotheses that over-simplify or over-estimate the influence of underlying causes, thereby failing to capture the complex interplay between several factors. Our causal models also show a new connection between generalization and MI attacks via their shared causal factors. Our causal models have high predictive power (0.90), i.e., their analytical predictions match with observations in unseen experiments often, which makes analysis via them a pragmatic alternative.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/27/2019

Alleviating Privacy Attacks via Causal Learning

Machine learning models, especially deep neural networks have been shown...
research
11/18/2021

Enhanced Membership Inference Attacks against Machine Learning Models

How much does a given trained model leak about each individual data reco...
research
09/05/2017

The Unintended Consequences of Overfitting: Training Data Inference Attacks

Machine learning algorithms that are applied to sensitive data pose a di...
research
05/24/2018

Generative Model: Membership Attack,Generalization and Diversity

This paper considers membership attacks to deep generative models, which...
research
12/03/2018

Generalization in anti-causal learning

The ability to learn and act in novel situations is still a prerogative ...
research
06/12/2023

Gaussian Membership Inference Privacy

We propose a new privacy notion called f-Membership Inference Privacy (f...
research
05/26/2021

Intriguing Parameters of Structural Causal Models

In recent years there has been a lot of focus on adversarial attacks, es...

Please sign up or login with your details

Forgot password? Click here to reset