arXiv:2412.05183cs.LGcs.CR2024-12中稿 · IEEE ICNC 25被引 2

增量学习中模型越准,隐私泄露风险越高

Privacy Drift: Evolving Privacy Concerns in Incremental Learning

  • 提出隐私漂移概念,分析模型更新时隐私泄露的变化
  • 实验发现模型性能提升会加剧成员推理攻击风险
  • 适合关注联邦学习隐私安全的研究者和工程师

在机器学习不断发展背景下,联邦学习(FL)实现了去中心化训练并保护用户数据隐私。本文提出“隐私漂移”这一新概念,类比于众所周知的“概念漂移”。当数据分布随时间变化导致模型准确率波动时,隐私漂移则描述了模型在增量训练过程中私有信息泄露程度的变化。通过严格实验,研究了隐私漂移在联邦学习系统中的动态特性,重点分析模型更新与数据分布偏移如何影响模型对成员推理攻击(MIA)的敏感性。实验基于从CIFAR-100(加拿大高级研究院,100类)衍生的定制数据集,验证了数据与概念漂移对隐私的影响。结果揭示模型性能提升可能带来更高的隐私风险,两者间存在复杂权衡。本工作为面向隐私的机器学习研究奠定基础,旨在实现去中心化环境中模型准确率与数据隐私的精细平衡。

原文摘要 · Abstract (English)

In the evolving landscape of machine learning (ML), Federated Learning (FL) presents a paradigm shift towards decentralized model training while preserving user data privacy. This paper introduces the concept of ``privacy drift", an innovative framework that parallels the well-known phenomenon of concept drift. While concept drift addresses the variability in model accuracy over time due to changes in the data, privacy drift encapsulates the variation in the leakage of private information as models undergo incremental training. By defining and examining privacy drift, this study aims to unveil the nuanced relationship between the evolution of model performance and the integrity of data privacy. Through rigorous experimentation, we investigate the dynamics of privacy drift in FL systems, focusing on how model updates and data distribution shifts influence the susceptibility of models to privacy attacks, such as membership inference attacks (MIA). Our results highlight a complex interplay between model accuracy and privacy safeguards, revealing that enhancements in model performance can lead to increased privacy risks. We provide empirical evidence from experiments on customized datasets derived from CIFAR-100 (Canadian Institute for Advanced Research, 100 classes), showcasing the impact of data and concept drift on privacy. This work lays the groundwork for future research on privacy-aware machine learning, aiming to achieve a delicate balance between model accuracy and data privacy in decentralized environments.

联邦学习隐私安全增量学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。