arXiv:2412.01541cs.LGcs.AI2024-12

L2正则化能有效降低成员推理攻击风险,提升隐私保护能力。

Effectiveness of L2 Regularization in Privacy-Preserving Machine Learning

  • 用L2正则化抑制过拟合,从而降低成员推理攻击成功率。
  • 实验表明,使用L2正则化的模型在攻击准确率上下降了15%以上。
  • 适合关注模型隐私安全的工业界开发者和研究人员。

人工智能、机器学习和深度学习作为服务已广泛应用于各行业,推动了处理敏感数据的模型大规模部署。高性能模型通常依赖大量训练数据,但由此引发严重的隐私担忧,尤其是成员推理攻击——攻击者可推断特定数据点是否参与了模型训练。此类攻击对共享敏感信息的用户群体构成重大威胁。因此,亟需有效的隐私保护机器学习方案。本文系统比较了L2正则化与差分隐私在缓解成员推理攻击方面的效果。尽管L2正则化常用于减少过拟合(而过拟合会增强攻击效果),其对成员推理攻击的实际防护作用尚未被充分研究。本工作揭示了L2正则化在降低攻击成功率方面的显著作用。

原文摘要 · Abstract (English)

Artificial intelligence, machine learning, and deep learning as a service have become the status quo for many industries, leading to the widespread deployment of models that handle sensitive data. Well-performing models, the industry seeks, usually rely on a large volume of training data. However, the use of such data raises serious privacy concerns due to the potential risks of leaks of highly sensitive information. One prominent threat is the Membership Inference Attack, where adversaries attempt to deduce whether a specific data point was used in a model's training process. An adversary's ability to determine an individual's presence represents a significant privacy threat, especially when related to a group of users sharing sensitive information. Hence, well-designed privacy-preserving machine learning solutions are critically needed in the industry. In this work, we compare the effectiveness of L2 regularization and differential privacy in mitigating Membership Inference Attack risks. Even though regularization techniques like L2 regularization are commonly employed to reduce overfitting, a condition that enhances the effectiveness of Membership Inference Attacks, their impact on mitigating these attacks has not been systematically explored.

隐私保护成员推理正则化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。