NeurIPS 2024poster10 citations

PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining

Mishaal Kazmi, Hadrien Lautraite, Alireza Akbari, Qiaoyue Tang, Mauricio Soroco, Tao Wang, Sébastien Gambs, Mathias Lécuyer

Abstract

We present PANORAMIA, a privacy leakage measurement framework for machine learning models that relies on membership inference attacks using generated data as non-members. By relying on generated non-member data, PANORAMIA eliminates the common dependency of privacy measurement tools on in-distribution non-member data. As a result, PANORAMIA does not modify the model, training data, or training process, and only requires access to a subset of the training data. We evaluate PANORAMIA on ML models for image and tabular data classification, as well as on large-scale language models.

privacyauditingmachine learningdifferential privacymembership inference attack
BibTeX
@inproceedings{
kazmi2024panoramia,
title={{PANORAMIA}: Privacy Auditing of Machine Learning Models without Retraining},
author={Mishaal Kazmi and Hadrien Lautraite and Alireza Akbari and Qiaoyue Tang and Mauricio Soroco and Tao Wang and S{\'e}bastien Gambs and Mathias L{\'e}cuyer},
booktitle={The Thirty-eighth Annual Conference on Neural Information Processing Systems},
year={2024},
url={https://openreview.net/forum?id=5atraF1tbg}
}
PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining · NeurIPS 2024