发表机构
University of the West of England(西英格兰大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究利用重尾自正则化框架下的廉价谱度量(如稳定秩和Log alpha-Norm)预测成员推理攻击的隐私泄露,发现其关联强于传统泛化差距,为可扩展隐私审计提供了新方向。
AI 中文摘要
成员推理攻击(MIA)被广泛用于审计机器学习模型的隐私泄露风险,然而当前最先进的攻击需要训练计算成本高昂的影子模型,使得大规模隐私评估不切实际。在本工作中,我们研究了源自重尾自正则化框架的廉价谱度量是否可以作为MIA脆弱性的代理指标。我们在图像和表格分类任务上评估了多种WeightWatcher谱度量,并将其与MIA隐私泄露的关系与传统的泛化度量进行比较。跨数据集而言,稳定秩与整体MIA成功率表现出强正相关,而Log alpha-Norm在低假阳性区间与MIA脆弱性呈现一致的负相关。这些关联被观察到强于使用泛化差距所得的结果。结果表明,神经网络谱可能包含未被传统过拟合度量完全捕获的隐私泄露信息,从而激励谱分析作为可扩展隐私审计的一个有前景的方向。
英文摘要
Membership inference attacks (MIAs) are widely used to audit the privacy disclosure risk of machine learning models, however current state-of-the-art attacks require training computationally expensive shadow models, making large-scale privacy evaluation impractical. In this work, we investigate whether inexpensive spectral metrics derived from the heavy-tailed self-regularisation framework can serve as proxies for MIA vulnerability. We evaluate several WeightWatcher spectral metrics on image and tabular classification tasks and compare their relationship with MIA privacy leakage against conventional measures of generalisation. Across datasets, stable rank exhibits a strong positive correlation with overall MIA success, while Log alpha-Norm shows a consistent negative correlation with MIA vulnerability at the low false-positive regime. These associations are observed to be stronger than those obtained using the generalisation gap. The results indicate that neural network spectra may contain information about privacy leakage that is not fully captured by conventional measures of overfitting, motivating spectral analysis as a promising direction for scalable privacy auditing.