The Privacy Onion Effect: Memorization is Relative

06/21/2022
by   Nicholas Carlini, et al.
0

Machine learning models trained on private datasets have been shown to leak their private data. While recent work has found that the average data point is rarely leaked, the outlier samples are frequently subject to memorization and, consequently, privacy leakage. We demonstrate and analyse an Onion Effect of memorization: removing the "layer" of outlier points that are most vulnerable to a privacy attack exposes a new layer of previously-safe points to the same attack. We perform several experiments to study this effect, and understand why it occurs. The existence of this effect has various consequences. For example, it suggests that proposals to defend against memorization without training with rigorous privacy guarantees are unlikely to be effective. Further, it suggests that privacy-enhancing technologies such as machine unlearning could actually harm the privacy of other users.

READ FULL TEXT

page 13

page 14

research
08/17/2022

On the Privacy Effect of Data Enhancement via the Lens of Memorization

Machine learning poses severe privacy concerns as it is shown that the l...
research
06/08/2020

Provable trade-offs between private robust machine learning

Historically, machine learning methods have not been designed with secur...
research
10/04/2021

Towards General-purpose Infrastructure for Protecting Scientific Data Under Study

The scientific method presents a key challenge to privacy because it req...
research
03/31/2022

Truth Serum: Poisoning Machine Learning Models to Reveal Their Secrets

We introduce a new class of attacks on machine learning models. We show ...
research
10/06/2022

CANIFE: Crafting Canaries for Empirical Privacy Measurement in Federated Learning

Federated Learning (FL) is a setting for training machine learning model...
research
09/21/2022

Measuring and Controlling Split Layer Privacy Leakage Using Fisher Information

Split learning and inference propose to run training/inference of a larg...
research
02/26/2020

Practicing Safe Browsing: Understanding How and Why University Students Use Virtual Private Networks

Despite their name and stated goal, Virtual Private Networks (VPNs) ofte...

Please sign up or login with your details

Forgot password? Click here to reset