arXiv · 2402.09477
PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining
Abstract
We present PANORAMIA, a privacy leakage measurement framework for machine learning models that relies on membership inference attacks using generated data as non-members. By relying on generated non-member data, PANORAMIA eliminates the common dependency of privacy measurement tools on in-distribution non-member data. As a result, PANORAMIA does not modify the model, training data, or training process, and only requires access to a subset of the training data. We evaluate PANORAMIA on ML models for image and tabular data classification, as well as on large-scale language models.
Explore related subjects
Keep this discovery
Mishaal Kazmi, Hadrien Lautraite, Alireza Akbari, Qiaoyue Tang, Mauricio Soroco, Tao Wang, Sébastien Gambs, Mathias Lécuyer. 2024-02-12. PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining. https://arxiv.org/abs/2402.09477
Cite the original work for its findings. Save a collection to share your selection of sources.