In a new 'unseen class' setting for membership inference, quantile regression attacks outperform shadow model attacks, which fall to the level of a global-threshold baseline.
Quantifying Privacy Risks of Public Statistics to Residents of Subsidized Housing
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
As the U.S. Census Bureau implements its controversial new disclosure avoidance system, researchers and policymakers debate the necessity of new privacy protections for public statistics. With experiments on both public statistics and synthetic microdata, we explore a particular privacy concern: respondents in subsidized housing may deliberately not mention unauthorized children and other household members for fear of being discovered and evicted. By combining public statistics from the Decennial Census and the Department of Housing and Urban Development, we demonstrate a simple, inexpensive reconstruction attack that could identify subsidized households living in violation of occupancy guidelines in 2010. Experiments on synthetic data suggest that a random swapping mechanism similar to the Census Bureau's 2010 disclosure avoidance measures does not significantly reduce the precision of this attack, while a differentially private mechanism similar to the 2020 disclosure avoidance system does. Our results provide a valuable example for policymakers seeking trustworthy public statistics.
citation-role summary
citation-polarity summary
fields
cs.LG 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
unclear 1representative citing papers
citing papers explorer
-
Membership Inference Attacks for Unseen Classes
In a new 'unseen class' setting for membership inference, quantile regression attacks outperform shadow model attacks, which fall to the level of a global-threshold baseline.