Slide 15
Slide 15 text
“Was this in the training data?”
‣ Given a blackbox machine learning model,
can you guess if a data sample was in the training data?
*Blackbox: no info about model detail; Only access to the API to send input & receive
result
‣ [Shokri+ 2017] “Membership Inference Attacks against
Machine Learning Models” (IEEE Symposium on Security and Privacy)
‣ Important in real world situations
‣ e.g., “ML as a Service” like Google, Amazon, or MS …
‣ e.g., Private information: Medical records, location, purchase history, …
‣ “Trust, but verify” (Доверяй, но проверяй)
!15