Machine learning models are increasingly utilized across impactful domains to predict individual outcomes. As such, many models provide algorithmic recourse to individuals who receive negative outcomes. However, recourse can be leveraged by adversaries to disclose private information. This work presents the first attempt at mitigating such attacks. We present two novel methods to generate differentially private recourse: Differentially Private Model (DPM) and Laplace Recourse (LR). Using logistic regression classifiers and real world and synthetic datasets, we find that DPM and LR perform well in reducing what an adversary can infer, especially at low FPR. When training dataset size is large enough, we find particular success in preventing privacy leakage while maintaining model and recourse accuracy with our novel LR method.
翻译:机器学习模型越来越多地应用于具有重大影响的领域,以预测个体结果。因此,许多模型为获得负面结果的个体提供算法救济措施(algorithmic recourse)。然而,对手可能会利用这一救济措施泄露隐私信息。本研究首次尝试缓解此类攻击。我们提出了两种生成差分隐私(differentially private)救济措施的新方法:差分隐私模型(DPM)和拉普拉斯救济(LR)。利用逻辑回归分类器及真实世界与合成数据集,我们发现DPM和LR能有效降低对手可推断的信息量,尤其是在低假阳性率(FPR)条件下。当训练数据集规模足够大时,我们的新型LR方法在保持模型与救济措施准确性的同时,能有效防止隐私泄露,取得了显著成效。