paper-with-me

홈 › Papers

On the Impact of Uncertainty and Calibration on Likelihood-Ratio Membership Inference Attacks

2024-02-16 · Meiyi Zhu, Caili Guo, Chunyan Feng, Osvaldo Simeone

In a membership inference attack (MIA), an attacker exploits the overconfidence exhibited by typical machine learning models to determine whether a specific data point was used to train a target model. In this paper, we analyze the performance of the likelihood ratio attack (LiRA) within an information-theoretical framework that allows the investigation of the impact of the aleatoric uncertainty in the true data generation process, of the epistemic uncertainty caused by a limited training data set, and of the calibration level of the target model. We compare three different settings, in which the attacker receives decreasingly informative feedback from the target model: confidence vector (CV) disclosure, in which the output probability vector is released; true label confidence (TLC) disclosure, in which only the probability assigned to the true label is made available by the model; and decision set (DS) disclosure, in which an adaptive prediction set is produced as in conformal prediction. We derive bounds on the advantage of an MIA adversary with the aim of offering insights into the impact of uncertainty and calibration on the effectiveness of MIAs. Simulation results demonstrate that the derived analytical bounds predict well the effectiveness of MIAs.

📄 PDF Abstract BibTeX arXiv:2402.10686

Code (0)

등록된 구현이 없습니다.

Tasks

Conformal PredictionInference AttackMembership Inference Attack

Methods 이 논문이 사용한 방법론

SET Dynamic Sparse Training method where weight mask is updated randomly periodically

Similar Papers 제목 키워드 기반

Automatic Calibration for Membership Inference Attack on Large Language Models

2025-05-06 · Saleh Zare Zade, Yao Qiang, Xiangyu Zhou, Hui Zhu 외

Membership Inference Attacks (MIAs) have recently been employed to determine whether a specific text was part of the pre-training data of Large Language Models (LLMs). However, existing methods often misinfer non-members…

Inference AttackMembership Inference Attack

Calibration Error Estimation Using Fuzzy Binning

2023-04-30 · Geetanjali Bihani, Julia Taylor Rayz

Neural network-based decisions tend to be overconfident, where their raw outcome probabilities do not align with the true decision probabilities. Calibration of neural networks is an essential step towards more reliable …

Studying the Impact of Augmentations on Medical Confidence Calibration

2023-08-23 · Adrit Rao, Joon-Young Lee, Oliver Aalami

The clinical explainability of convolutional neural networks (CNN) heavily relies on the joint interpretation of a model's predicted diagnostic label and associated confidence. A highly certain or uncertain model can sig…

Decision MakingDiagnostic

Amortized Conditional Normalized Maximum Likelihood: Reliable Out of Distribution Uncertainty Estimation

2020-11-05 · Aurick Zhou, Sergey Levine

While deep neural networks provide good performance for a range of challenging tasks, calibration and uncertainty estimation remain major challenges, especially under distribution shift. In this paper, we propose the amo…

Bayesian Inference

Amortized Conditional Normalized Maximum Likelihood

2020-09-28 · Aurick Zhou, Sergey Levine

While deep neural networks provide good performance for a range of challenging tasks, calibration and uncertainty estimation remain major challenges. In this paper, we propose the amortized conditional normalized maximum…

Bayesian Inference