We propose a new privacy notion called $f$-Membership Inference Privacy ($f$-MIP), which explicitly considers the capabilities of realistic adversaries under the membership inference attack threat model. By doing so $f$-MIP offers interpretable privacy guarantees and improved utility (e.g., better classification accuracy). Our novel theoretical analysis of likelihood ratio-based membership inference attacks on noisy stochastic gradient descent (SGD) results in a parametric family of $f$-MIP guarantees that we refer to as $\mu$-Gaussian Membership Inference Privacy ($\mu$-GMIP). Our analysis additionally yields an analytical membership inference attack that offers distinct advantages over previous approaches. First, unlike existing methods, our attack does not require training hundreds of shadow models to approximate the likelihood ratio. Second, our analytical attack enables straightforward auditing of our privacy notion $f$-MIP. Finally, our analysis emphasizes the importance of various factors, such as hyperparameters (e.g., batch size, number of model parameters) and data specific characteristics in controlling an attacker's success in reliably inferring a given point's membership to the training set. We demonstrate the effectiveness of our method on models trained across vision and tabular datasets.
翻译:我们提出了一种新的隐私概念——$f$-成员推断隐私($f$-MIP),该概念明确考虑了成员推断攻击威胁模型下现实攻击者的能力。通过这一设计,$f$-MIP提供了可解释的隐私保障并提升了效用(例如,更好的分类准确率)。我们对含噪随机梯度下降(SGD)中基于似然比的成员推断攻击进行了新颖的理论分析,由此得到一组参数化$f$-MIP保证族,我们将其称为$\mu$-高斯成员推断隐私($\mu$-GMIP)。该分析还得出了一种解析式成员推断攻击方法,相较于先前方法具有显著优势。首先,与现有方法不同,我们的攻击无需训练数百个影子模型来近似似然比。其次,我们的解析攻击能够直接审计我们的隐私概念$f$-MIP。最后,我们的分析强调了超参数(如批大小、模型参数数量)和数据特征等因素在控制攻击者成功可靠推断训练集中特定数据点成员关系中的重要性。我们在视觉和表格数据集上训练模型验证了该方法的效果。