发现数据剪枝会泄露隐私,提出新型溯源推理方法
Data Lineage Inference: Uncovering Privacy Vulnerabilities of Dataset Pruning
- 提出数据溯源推理新范式,从剪枝阶段识别冗余数据
- 无需模型即可精准定位冗余数据集,仅需少量先验知识
- 揭示不同剪枝方法和比例的隐私风险差异,给出防护指标
本文系统研究机器学习中数据剪枝带来的隐私问题。首次发现:即使冗余数据仅在训练前使用,其剪枝阶段的归属仍可能被攻击者检测到。由于该过程完全位于模型训练之前,传统基于模型输出的隐私推理方法失效。为此,我们提出全新任务「以数据为中心的成员推断」,并构建首个数据溯源推理(DaLI)范式,设计四种基于阈值的攻击方法:WhoDis、CumDis、ArraDis 和 SpiDis。实验表明,即便无下游模型访问权限,攻击者仅凭有限先验知识即可准确识别冗余数据集。此外,我们发现不同剪枝方法存在不同程度的隐私泄露,同一方法在不同剪枝比例下也呈现不同风险。通过深入分析,提出「充盈度评分」(Brimming score),为具备隐私保护意识的剪枝方法选择提供指导。
原文摘要 · Abstract (English)
In this work, we systematically explore the data privacy issues of dataset pruning in machine learning systems. Our findings reveal, for the first time, that even if data in the redundant set is solely used before model training, its pruning-phase membership status can still be detected through attacks. Since this is a fully upstream process before model training, traditional model output-based privacy inference methods are completely unsuitable. To address this, we introduce a new task called Data-Centric Membership Inference and propose the first ever data-centric privacy inference paradigm named Data Lineage Inference (DaLI). Under this paradigm, four threshold-based attacks are proposed, named WhoDis, CumDis, ArraDis and SpiDis. We show that even without access to downstream models, adversaries can accurately identify the redundant set with only limited prior knowledge. Furthermore, we find that different pruning methods involve varying levels of privacy leakage, and even the same pruning method can present different privacy risks at different pruning fractions. We conducted an in-depth analysis of these phenomena and introduced a metric called the Brimming score to offer guidance for selecting pruning methods with privacy protection in mind.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。