arXiv · 2410.07632
Provable Privacy Attacks on Trained Shallow Neural Networks
Abstract
We study what provable privacy attacks can be shown for trained 2-layer ReLU neural networks, focusing on two types of attacks: membership inference and data reconstruction. We prove that theoretical results on the implicit bias of 2-layer neural networks can be used to provably identify with high probability whether a given point was used in the training set in a high-dimensional, nearly orthogonal setting, and can also be used to construct a finite set of which at least a constant fraction are training points in a univariate setting. To the best of our knowledge, our work is the first to show provable vulnerabilities in this implicit-bias-driven setting.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Guy Smorodinsky, Gal Vardi, Itay Safran. 2024-10-10. Provable Privacy Attacks on Trained Shallow Neural Networks. https://arxiv.org/abs/2410.07632
Cite the original work for its findings. Save a collection to share your selection of sources.