Membership inference attacks (MIA) can reveal whether a particular data point was part of the training dataset, potentially exposing sensitive information about individuals. This article explores the fundamental statistical limitations associated with MIAs on machine learning models. More precisely, we first derive the statistical quantity that governs the effectiveness and success of such attacks. Then, we investigate several situations for which we provide bounds on this quantity of interest. This allows us to infer the accuracy of potential attacks as a function of the number of samples and other structural parameters of learning models, which in some cases can be directly estimated from the dataset.
翻译:成员推断攻击(MIA)能够揭示特定数据点是否属于训练数据集,从而可能暴露个体的敏感信息。本文探讨了针对机器学习模型的成员推断攻击所相关的根本统计限制。具体而言,我们首先推导出控制此类攻击有效性和成功率的统计量。随后,我们研究了几种情况,并针对这些情况给出了该目标量的界限。这使得我们能够根据样本数量和学习模型的其他结构参数推断潜在攻击的准确性,在某些情况下,这些参数可直接从数据集中估计得出。