PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 18, 202174 citationsOpen Access

Membership Privacy for Machine Learning Models Through Knowledge Transfer

VSVirat ShejwalkarGoogle (United States)AHAmir HoumansadrAmherst College

Key Points

  • This work aims to enhance membership privacy in machine learning models while maintaining high classification performance.
  • Developed a new defense mechanism called distillation for membership privacy (DMP) against membership inference attacks (MIAs).
  • Employed knowledge distillation to train models that protect against MIAs and preserve utility.
  • Established a new criterion for tuning data used in knowledge transfer to improve membership privacy.
  • DMP improved classification accuracy by ~100% over adversarial regularization for DenseNet on CIFAR100.
  • At 53.7% MIA risk, DMP-trained DenseNet achieved 65.3% accuracy compared to 33.6% accuracy from adversarially regularized models.

Abstract

Large capacity machine learning (ML) models are prone to membership inference attacks (MIAs), which aim to infer whether the target sample is a member of the target model's training dataset. The serious privacy concerns due to the membership inference have motivated multiple defenses against MIAs, e.g., differential privacy and adversarial regularization. Unfortunately, these defenses produce ML models with unacceptably low classification performances. Our work proposes a new defense, called distillation for membership privacy (DMP), against MIAs that preserves the utility of the resulting models significantly better than prior defenses. DMP leverages knowledge distillation to train ML models with membership privacy. We provide a novel criterion to tune the data used for knowledge transfer in order to amplify the membership privacy of DMP. Our extensive evaluation shows that DMP provides significantly better tradeoffs between membership privacy and classification accuracies compared to state-of-the-art MIA defenses. For instance, DMP achieves ~100% accuracy improvement over adversarial regularization for DenseNet trained on CIFAR100, for similar membership privacy (measured using MIA risk): when the MIA risk is 53.7%, adversarially regularized DenseNet is 33.6% accurate, while DMP-trained DenseNet is 65.3% accurate. We have released our code at github.com/vrt1shjwlkr/AAAI21-MIA-Defense.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Shejwalkar et al. (2021) studied this question.

synapsesocial.com/papers/6a0f22c95f469783126c948ehttps://doi.org/10.1609/aaai.v35i11.17150
Ask AI
Helpful
Bookmark
Share
View Full Paper