paper-with-me

홈 › Papers

Privacy Side Channels in Machine Learning Systems

2023-09-11 · Edoardo Debenedetti, Giorgio Severi, Nicholas Carlini, Christopher A. Choquette-Choo, Matthew Jagielski, Milad Nasr, Eric Wallace, Florian Tramèr

Most current approaches for protecting privacy in machine learning (ML) assume that models exist in a vacuum. Yet, in reality, these models are part of larger systems that include components for training data filtering, output monitoring, and more. In this work, we introduce privacy side channels: attacks that exploit these system-level components to extract private information at far higher rates than is otherwise possible for standalone models. We propose four categories of side channels that span the entire ML lifecycle (training data filtering, input preprocessing, output post-processing, and query filtering) and allow for enhanced membership inference, data extraction, and even novel threats such as extraction of users' test queries. For example, we show that deduplicating training data before applying differentially-private training creates a side-channel that completely invalidates any provable privacy guarantees. We further show that systems which block language models from regenerating training data can be exploited to exfiltrate private keys contained in the training set--even if the model did not memorize these keys. Taken together, our results demonstrate the need for a holistic, end-to-end privacy analysis of machine learning systems.

📄 PDF Abstract BibTeX arXiv:2309.05610

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Making Translators Privacy-aware on the User's Side

2023-12-07 · Ryoma Sato

We propose PRISM to enable users of machine translation systems to preserve the privacy of data on their own initiative. There is a growing demand to apply machine translation systems to data that require privacy protect…

Machine TranslationTranslation

Private Image Reconstruction from System Side Channels Using Generative Models

2021-01-01 · ICLR 2021 1 · Yuanyuan Yuan, Shuai Wang, Junping Zhang

System side channels denote effects imposed on the underlying system and hardware when running a program, such as its accessed CPU cache lines. Side channel analysis (SCA) allows attackers to infer program secrets based …

CPUImage ReconstructionSide Channel Analysis

DuetFace: Collaborative Privacy-Preserving Face Recognition via Channel Splitting in the Frequency Domain

2022-07-15 · Yuxi Mi, Yuge Huang, Jiazhen Ji, Hongquan Liu 외

With the wide application of face recognition systems, there is rising concern that original face images could be exposed to malicious intents and consequently cause personal privacy breaches. This paper presents DuetFac…

Collaborative InferenceFace RecognitionPrivacy Preserving

Uncovering the Dark Side of Telegram: Fakes, Clones, Scams, and Conspiracy Movements

2021-11-26 · Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini, Jie Wu

Telegram is one of the most used instant messaging apps worldwide. Some of its success lies in providing high privacy protection and social network features like the channels -- virtual rooms in which only the admins can…

Privacy Preserving

Recursive Privacy-Preserving Estimation Over Markov Fading Channels

2025-06-03 · Jie Huang, Fanlin Jia, Xiao He

In industrial applications, the presence of moving machinery, vehicles, and personnel, contributes to the dynamic nature of the wireless channel. This time variability induces channel fading, which can be effectively mod…

Privacy PreservingState Estimation