Score breakdown

Membership Inference Attacks Against Machine Learning Models

paper-0100 · paper · 2017

Reza Shokri et al.

Showed models leak whether your data was in the training set.

Abstract

We quantitatively investigate how machine learning models leak information about the individual data records on which they were trained. We focus on the basic membership inference attack: given a data record and black-box access to a model, determine if the record was in the model's training dataset. To perform membership inference against a target model, we make adversarial use of machine learning and train our own inference model to recognize differences in the target model's predictions on the inputs that it trained on versus the inputs that it did not train on. We empirically evaluate our inference techniques on classification models trained by commercial "machine learning as a service" providers such as Google and Amazon. Using realistic datasets and classification tasks, including a hospital discharge dataset whose membership is sensitive from the privacy perspective, we show that these models can be vulnerable to membership inference attacks. We then investigate the factors that influence this leakage and evaluate mitigation strategies. [OpenAlex]

Academic, score -0.1798

MetricStatusValueNorm.WeightContributionSourceConfidenceLicenseProvenance
citation_countpresent4231.00.0190410.50.00952OpenAlexhighOpenAlex, CC0 metadatalink
library_holdingsmissingrecorded as missing, penalized by rule, never imputed−0.1recorded as missing; penalized by rule, never imputed
readership_persistencepresent11.00.7142860.050.035714OpenAlexmediumOpenAlex, CC0 metadatalink
syllabus_adoptionsmissingrecorded as missing, penalized by rule, never imputed−0.125recorded as missing; penalized by rule, never imputed

Broad Influence, score 0.0895

MetricStatusValueNorm.WeightContributionSourceConfidenceLicenseProvenance
citation_countpresent4231.00.0190410.20.003808OpenAlexhighOpenAlex, CC0 metadatalink
library_holdingsmissingrecorded as missing, penalized by rule, never imputed−0.125recorded as missing; penalized by rule, never imputed
readership_persistencepresent11.00.7142860.40.285714OpenAlexmediumOpenAlex, CC0 metadatalink
syllabus_adoptionsmissingrecorded as missing, penalized by rule, never imputed−0.075recorded as missing; penalized by rule, never imputed

Governance Practitioner, score -0.2488

MetricStatusValueNorm.WeightContributionSourceConfidenceLicenseProvenance
citation_countpresent4231.00.0190410.250.00476OpenAlexhighOpenAlex, CC0 metadatalink
library_holdingsmissingrecorded as missing, penalized by rule, never imputed−0.15recorded as missing; penalized by rule, never imputed
readership_persistencepresent11.00.7142860.10.071429OpenAlexmediumOpenAlex, CC0 metadatalink
syllabus_adoptionsmissingrecorded as missing, penalized by rule, never imputed−0.175recorded as missing; penalized by rule, never imputed

A rank is not a verdict on intrinsic worth. It is a transparent output of declared evidence, weights, and missing-data rules at a specific release date.

Disagree with this rank or a number? Challenge it with your evidence. Every challenge gets a public identifier and a published resolution.