Pith. sign in

REVIEW 1 cited by

Measuring Unintended Memorisation of Unique Private Features in Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2202.08099 v1 pith:AUDBGG6Y submitted 2022-02-16 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords uniquefeaturesnetworksneuraltrainingdatainformationmodel
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Neural networks pose a privacy risk to training data due to their propensity to memorise and leak information. Focusing on image classification, we show that neural networks also unintentionally memorise unique features even when they occur only once in training data. An example of a unique feature is a person's name that is accidentally present on a training image. Assuming access to the inputs and outputs of a trained model, the domain of the training data, and knowledge of unique features, we develop a score estimating the model's sensitivity to a unique feature by comparing the KL divergences of the model's output distributions given modified out-of-distribution images. Our results suggest that unique features are memorised by multi-layer perceptrons and convolutional neural networks trained on benchmark datasets, such as MNIST, Fashion-MNIST and CIFAR-10. We find that strategies to prevent overfitting (e.g.\ early stopping, regularisation, batch normalisation) do not prevent memorisation of unique features. These results imply that neural networks pose a privacy risk to rarely occurring private information. These risks can be more pronounced in healthcare applications if patient information is present in the training data.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Membership Inference Risks in Quantized Models: A Theoretical and Empirical Study

    stat.ML 2025-02 conditional novelty 6.0 of 10

    Quantizers can be ranked by privacy using r_Q, a rate constant built from the loss gap and variance of low-loss quantized checkpoints along the training trajectory.

Pith tools