{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/privacy-risk-in-machine-learning-analyzing","title":"Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting","arxiv_id":"1709.01604","date":"2017-09-05","proceeding":null,"authors":["Samuel Yeom","Irene Giacomelli","Matt Fredrikson","Somesh Jha"],"abstract":"Machine learning algorithms, when applied to sensitive data, pose a distinct\nthreat to privacy. A growing body of prior work demonstrates that models\nproduced by these algorithms may leak specific private information in the\ntraining data to an attacker, either through the models' structure or their\nobservable behavior. However, the underlying cause of this privacy risk is not\nwell understood beyond a handful of anecdotal accounts that suggest overfitting\nand influence might play a role.\n  This paper examines the effect that overfitting and influence have on the\nability of an attacker to learn information about the training data from\nmachine learning models, either through training set membership inference or\nattribute inference attacks. Using both formal and empirical analyses, we\nillustrate a clear relationship between these factors and the privacy risk that\narises in several popular machine learning algorithms. We find that overfitting\nis sufficient to allow an attacker to perform membership inference and, when\nthe target attribute meets certain conditions about its influence, attribute\ninference attacks. Interestingly, our formal analysis also shows that\noverfitting is not necessary for these attacks and begins to shed light on what\nother factors may be in play. Finally, we explore the connection between\nmembership inference and attribute inference, showing that there are deep\nconnections between the two that lead to effective new attacks.","url_abs":"http://arxiv.org/abs/1709.01604v5","url_pdf":"http://arxiv.org/pdf/1709.01604v5.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"privacy-risk-in-machine-learning-analyzing","repo_url":"https://github.com/samuel-yeom/ml-privacy-csf18","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"attribute","task_name":"Attribute"},{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1709.01604","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}