Pith. sign in

REVIEW 2 cited by

Differentially Private Counterfactuals via Functional Mechanism

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2208.02878 v1 pith:5AM5U6SL submitted 2022-08-04 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords modelcounterfactualscounterfactualexplanationdifferentiallyframeworkfunctionalmechanism
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Counterfactual, serving as one emerging type of model explanation, has attracted tons of attentions recently from both industry and academia. Different from the conventional feature-based explanations (e.g., attributions), counterfactuals are a series of hypothetical samples which can flip model decisions with minimal perturbations on queries. Given valid counterfactuals, humans are capable of reasoning under ``what-if'' circumstances, so as to better understand the model decision boundaries. However, releasing counterfactuals could be detrimental, since it may unintentionally leak sensitive information to adversaries, which brings about higher risks on both model security and data privacy. To bridge the gap, in this paper, we propose a novel framework to generate differentially private counterfactual (DPC) without touching the deployed model or explanation set, where noises are injected for protection while maintaining the explanation roles of counterfactual. In particular, we train an autoencoder with the functional mechanism to construct noisy class prototypes, and then derive the DPC from the latent prototypes based on the post-processing immunity of differential privacy. Further evaluations demonstrate the effectiveness of the proposed framework, showing that DPC can successfully relieve the risks on both extraction and inference attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Private Counterfactual Retrieval With Immutable Features

    cs.IT 2024-11 conditional novelty 6.0 of 10

    Proposes two PIR-based protocols for retrieving the exact nearest counterfactual while keeping the user's immutable feature set private, with communication costs 6d+3M and 9(d+M).

  2. Combining Machine Learning Defenses without Conflicts

    cs.CR 2024-11 conditional novelty 5.0 of 10

    A stage-and-risk-based decision rule predicts whether pairs of ML defenses conflict, with reported balanced accuracy of 90% on eight prior combinations and 81-86% on 30 new ones.

Pith tools