Empirical defenses for machine learning privacy forgo the provable guarantees of differential privacy in the hope of achieving higher utility while resisting realistic adversaries. We identify severe pitfalls in existing empirical privacy evaluations (based on membership inference attacks) that result in misleading conclusions. In particular, we show that prior evaluations fail to characterize the privacy leakage of the most vulnerable samples, use weak attacks, and avoid comparisons with practical differential privacy baselines. In 5 case studies of empirical privacy defenses, we find that prior evaluations underestimate privacy leakage by an order of magnitude. Under our stronger evaluation, none of the empirical defenses we study are competitive with a properly tuned, high-utility DP-SGD baseline (with vacuous provable guarantees).
翻译:经验性机器学习隐私防御放弃差分隐私的可证明保证,以期在抵抗现实攻击者时获得更高效用。我们识别出现有基于成员推断攻击的经验性隐私评测中存在的严重缺陷,这些缺陷导致了误导性结论。具体而言,我们证明先前的评测未能刻画最易受攻击样本的隐私泄露程度,使用了较弱的攻击手段,且回避了与实用差分隐私基线的比较。通过对5个经验性隐私防御案例的研究,我们发现先前的评测低估了隐私泄露程度达一个数量级。在采用更强评测方法后,我们研究的经验性防御方案均无法与经过恰当调优、具有高实用性的DP-SGD基线(其可证明保证具有无效性)相匹敌。