Method and device for determining the membership of training data used for training a machine learning data classification model

The proposed process and device improve data classification model security by using multiple partitions, control models, and decision-making models to accurately determine data belonging, addressing the limitations of current methods.

FR3155338A1Pending Publication Date: 2025-05-16THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023012499
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-15
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Current methods for determining whether data belongs to the learning data used for training a data classification model are inadequate, as they lack a comprehensive tool to compare membership inference models and determine their effectiveness on a given dataset.

Method used

A process and device that generate multiple partitions of data, train control models with the same structure as the target model, and use a combination of membership inference models and decision-making models to predict whether data belongs to the learning data, incorporating confidence scores for improved accuracy.

Benefits of technology

This approach enhances the performance of determining effective belonging or detecting real positives by combining multiple membership inference models and decision-making models, providing a more robust and accurate method compared to existing techniques.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method and device for determining membership of training data used for training a machine learning data classification model. This device for determining membership of training data used for training a target classification model (8) implements, on a set (10) of data to be processed, modules for: - generation (20) of a number N greater than 2 of distinct partitions of the set of data to be processed (10) into a first and a second subset of data, - calculation (22) by machine learning of N reference models (161,…,16N), of the same structure as said target model (8);-machine learning (24) on a first subset of reference models of at least two distinct membership inference models (261,…, 26P) each providing, for each data to be processed, a prediction of membership in the training data of the target model, - machine learning, on a second subset of reference models, of the parameters of at least one decision model (24) taking as input said membership predictions and providing as output a consolidated membership prediction. Figure for the abstract: Figure 1;
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method and device for determining membership in training data used for training a machine learning data classification model

[0001] The present invention relates to a method for determining membership of training data used for training a machine learning data classification model, called the target model.

[0002] The invention also relates to an associated device and an associated computer program.

[0003] The invention is in the field of security for applications using artificial intelligence.

[0004] Many applied systems, for example in the industrial, medical or military fields, use automatic data classification models, for example models based on artificial neural networks, which are trained by machine learning.

[0005] This type of classification model comprises a very large number of parameters, the values ​​of which are calculated and updated dynamically. It is necessary to learn the values ​​of the parameters defining a classification model; this parameter learning (also called training) is carried out in a training phase on very large amounts of data. Typically, such classification models take as input data, for example in vector or matrix form, of a known type, and provide as output a classification label for the data.

[0006] For example, the input data are images, of predetermined dimensions, and the classification labels represent predetermined classes, for example representative of types of object present in the scene represented by the image, according to the intended application.

[0007] The input data used for training, called training data, comes from either public or private databases. For certain applications requiring a certain level of security, for example medical or military applications, it is critical to protect the training data, and in particular to ensure that it is not possible to obtain information relating to the training data from a trained classification model.

[0008] Recent publications describe membership inference attack models. A membership inference attack model makes it possible to predict, based on a target classification model, whether a piece of data to be processed belongs or does not belong to the training data used to train the target model. This type of attack can then be implemented by a legitimate owner of data that has, for example, been hacked by a malicious third party on a server, to subsequently determine whether the hacked data has been used to train a classification model. Furthermore, knowledge of this type of attack makes it possible to subsequently strengthen the security of the data actually used in a machine learning phase of the parameters of a classification model by a legitimate actor.

[0009] The article by Di Wu, Saiyu Qi, Yong Qi, Qian Li, Bowen Cai, Qi Guo, Jingxian Cheng, “Understanding and defending against White-box membership inference attack in deep learning, Knowledge-Based Systems”, published in 2023, describes the use of membership inference attacks for a defensive purpose.

[0010] Several methods of membership inference attack are known, implementing membership inference models.

[0011] In particular, membership inference models requiring knowledge of the target model's structure are known. For example, in the case of a neural network, the structure includes the number of layers, the number of neurons per layer, the links between layers, the activation functions, and the weight values. In other words, all the parameters defining the target model are known. These membership inference models are part of so-called "white-box" attacks, where the target model is considered transparent.

[0012] For example, the article "Membership Inference Attack Using Self Influence Functions" by G. Cohen and R. Giryes published in 2022 describes a "white box" type membership inference attack using self-influence functions.

[0013] Membership inference attacks are also known on a target model that can be used to obtain a classification from data to be processed, but whose structure, and more generally its parameters, are unknown. These attacks are also called "black box" attacks, the target model being considered opaque, like a black box.

[0014] For example, the article "Membership inference attacks from first principles" by N. Carlini et al, published in IEEE Symposium on Security and Privacy, 2022, describes an attack of this type.

[0015] However, each known inference attack method has advantages and disadvantages, and their performance varies depending on the dataset to be processed.

[0016] There is currently no tool to compare membership inference models or to determine which model will produce better performance on a given dataset.

[0017] The aim of the invention is then to propose a method for determining membership in the training data of a classification model allowing to obtain improved performance, in particular in the determination of effective membership or detection of true positives.

[0018] To this end, the invention relates to a method for determining the membership of training data used for training a machine learning data classification model, called the target model, the method being implemented by a computing processor, and comprising, in a learning phase implemented on a set of data to be processed, the steps of:

[0019] - generation of a number N greater than 2 of distinct partitions of the set of data to be processed in a first and second subset of data,

[0020] - machine learning calculation of N reference models, each reference model having the same structure as said target model, the calculation includes learning the parameters of each reference model from a first subset of data from one of the partitions, to provide as output a classification substantially identical to that provided by the target model;

[0021] -machine learning on a first subset of reference models of at least two distinct membership inference models, each providing, for each data point to be processed, a prediction of membership or non-membership in the training data of the target model,

[0022] - machine learning, on a second subset of reference models, of parameters of at least one decision model taking as input said membership or non-membership predictions and providing as output a consolidated membership or non-membership prediction.

[0023] Advantageously, the proposed method for determining membership in training data combines at least two distinct membership inference models and implements a decision model. Preferably, the decision model also takes into account confidence scores for each membership inference model.

[0024] The method for determining membership of training data according to the invention may also have one or more of the following characteristics, taken independently or according to all technically conceivable combinations.

[0025] At least one of the membership inference models provides, for each data point to be processed, a confidence score associated with the prediction of membership or non- belonging to the target model's training data, and the machine learning of said at least one decision model takes said confidence scores as input.

[0026] Each distinct membership inference model provides, for each data to be processed, a confidence score associated with the prediction of membership or non-membership in the training data of the target model, and machine learning, on a second subset of control models, parameters of at least one decision model takes as input said predictions of membership or non-membership and the associated confidence scores provided by each distinct membership inference model.

[0027] The process further comprises an operational phase including, for at least one piece of data to be processed, the following steps: - implementation of each of said membership inference models on said data to be processed in order to obtain predictions of membership or non-membership and the associated confidence scores; - determination of a consolidated prediction of membership or non-membership of said data to be processed in the training data by application of said decision model on the predictions of membership or non-membership and the associated confidence scores.

[0028] The method implements a first membership inference model using knowledge of the parameters of the target model, and a second membership inference model without using the parameters of the target model.

[0029] A plurality of decision models are implemented including models of: logistic regression, random forest, adaptive amplification, gradient amplification, naive Bayesian model.

[0030] The method further includes a step of determining membership or non-membership to obtain a final prediction of membership or non-membership by combining the results of the decision models.

[0031] The combination of results is carried out by majority vote or weighted majority vote.

[0032] According to another aspect, the invention relates to a device for determining membership in training data used for training a machine learning data classification model, called the target model, the device comprising a computing processor, configured, in a learning phase, to perform on a set of data to be processed:

[0033] - a module for generating a number N greater than 2 of distinct partitions of the dataset to be processed in a first and second subset of data,

[0034] - a machine learning calculation module for N reference models, each a reference model having the same structure as said target model, the calculation involving the learning of the parameters of each reference model from the first subset of data of one of the partitions, to provide as output a classification substantially identical to that provided by the target model;

[0035] - a machine learning module on a first subset of models witnesses of at least two distinct membership inference models, each providing, for each data point to be processed, a prediction of membership or non-membership in the target model's training data,

[0036] - a machine learning module, on a second subset of models witnesses, parameters of at least one decision model taking as input said predictions of membership or non-membership and providing as output a consolidated prediction of membership or non-membership.

[0037] Advantageously, this device is configured to implement a method for determining membership in training data as briefly described above.

[0038] According to another aspect, the invention relates to an information storage medium, on which software instructions are stored for the execution of a method for determining membership in training data as briefly described above, when these instructions are executed by a programmable electronic device.

[0039] According to another aspect, the invention relates to a computer program comprising software instructions which, when implemented by a programmable electronic device, implement a method for determining membership in training data as briefly described above.

[0040] The invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the drawings in which:

[0041] [Fig-1] [Fig.1] is a schematic representation of the main modules of a device for determining membership of training data used for training a machine learning data classification model according to an embodiment;

[0042] [Fig.2] [Fig.2] is a synoptic diagram of the main steps of an embodiment of the membership determination process in the learning phase;

[0043] [Fig.3] [Fig.3] is a schematic illustration of a plurality of data partitions;

[0044] [Fig.4] [Fig.4] is a synoptic diagram of the main steps of an embodiment of the membership determination process in the operational phase.

[0045] Fig. 1 schematically represents the main modules of a device 2 for determining membership in the training data previously used for training a target classification model MC.

[0046] Device 2 is a programmable electronic device, e.g., a computer. In an alternative not shown, device 2 is formed of a plurality of interconnected programmable electronic devices.

[0047] The device 2 comprises at least one computing processor 4, an electronic memory unit 6, adapted to communicate via a communication bus 5.

[0048] In addition, device 2 also includes a communication interface with remote devices, via a chosen communication protocol, for example a wired protocol and / or a radio communication protocol, as well as a human-machine interface; these interfaces are made in a conventional way and are not shown in [Fig.1].

[0049] The electronic memory unit stores the target model (TM) 8, which is an input data classification model previously trained by machine learning on a training dataset.

[0050] The previously used training dataset is not known.

[0051] The target model is trained to classify input data represented in vector or matrix form of predetermined dimension(s).

[0052] For example, in an application, the input data are digital images of objects, to be classified into a predetermined set of classes.

[0053] Classification consists, for example, of associating a classification label (or classification tag) with each input data.

[0054] Many applications use this type of classification model for object recognition from digital images.

[0055] In one embodiment, the target model is implemented in the form of a neural network.

[0056] In a known manner, a neural network comprises an ordered succession of layers of neurons, each of which takes its inputs from the outputs of the previous layer.

[0057] More precisely, each layer comprises neurons taking their inputs from the outputs of the neurons of the previous layer, or from the input variables for the first layer.

[0058] Alternatively, more complex neural network structures can be envisaged with a layer that can be linked to a layer further away than the immediately preceding layer.

[0059] Each neuron is also associated with an operation, that is to say a type of processing, to be carried out by said neuron within the corresponding processing layer.

[0060] Each layer is connected to the other layers by a plurality of synapses. A synaptic weight is associated with each synapse, and each synapse forms a link between two neurons. It is often a real number, which takes on both positive and negative values. In some cases, the synaptic weight is a complex number.

[0061] Each neuron is designed to perform a weighted sum of the value(s) received from the neurons of the preceding layer, each value being multiplied by the respective synaptic weight of each synapse, or connection, between said neuron and the neurons of the preceding layer, and then to apply an activation function, typically a non-linear function, to said weighted sum, and to deliver at the output of said neuron, in particular to the neurons of the next layer connected to it, the value resulting from the application of the activation function. The activation function introduces non-linearity into the processing performed by each neuron. The sigmoid function, the hyperbolic tangent function, and the Heaviside function are examples of activation functions.

[0062] As an optional complement, each neuron is also capable of applying, in addition, a multiplicative factor, and an additive bias, to the output of the activation function, and the value delivered at the output of said neuron is then the product of the value of the multiplicative factor and the value from the activation function, plus the bias.

[0063] A convolutional neural network is also sometimes called a convolutional neural network or by the acronym CNN, which refers to the English term "Convolutional Neural Networks".

[0064] In a convolutional neural network, each neuron in the same layer exhibits exactly the same connection pattern as its neighboring neurons, but at different input positions. The connection pattern is called the convolutional kernel or, more commonly, the "kernel" in reference to the corresponding English term.

[0065] A fully connected layer of neurons is a layer in which the neurons of said layer are each connected to all the neurons of the preceding layer.

[0066] Such a type of layer is more often referred to by the English term "fully connected", and sometimes designated by the name "dense layer".

[0067] The values ​​of the weights, multipliers and biases where applicable are learned during a machine learning phase to perform the classification task.

[0068] The invention applies with all types of neural networks.

[0069] In general, it is assumed that the parameters of the target model, and in particular of the neural network forming the target model, are known, the parameters including the structures and values ​​of the weights learned by machine learning.

[0070] Besides the target model, the memory unit 6 also stores a set 10 of data 12; to be processed.

[0071] Each data to be processed 12; is a numerical data, represented in the same vector or matrix form as the input data of the target model 8, and of the same predetermined dimension(s).

[0072] The data to be processed are data likely to have been used during the training of the target model 8. Each data to be processed is an instance (or an example) of one of the output classes of the target model.

[0073] The dataset to be processed has a cardinality L, L being a positive integer, preferably greater than 2.

[0074] As an optional addition, the set 8 of data to be processed can be augmented by applying a data augmentation method, for example by image processing when the data to be processed are digital images (e.g., rotation, translation, vertical or horizontal flipping). This makes it possible, in particular, to ensure that a sufficient number of instances of the classes are available for the calculation of control models, described below.

[0075] The processor 4 is configured to implement a module 20 for generating a number N greater than 2 of distinct partitions of the data set to be processed into a first and a second subset of data.

[0076] It also includes a machine learning calculation module 22 of N reference models (RM) 16;... 16N, which are stored in the memory unit 6.

[0077] Each control model 16j is a classification model of the same structure as the target model 8, and the parameters of the control model are learned by machine learning on the first subset of data from one of the generated partitions, with the objective of obtaining a classification substantially identical to that of the target model, and in particular with the objective of obtaining an output statistical distribution similar to the output statistical distribution of the target model.

[0078] In other words, each control model "imitates" the target model, the control model being trained on a known training database (e.g. the first-subset of a chosen partition).

[0079] The processor 4 further comprises a machine learning module 24 on a first subset of reference models of at least two distinct membership inference models 26, ..., 26P, each providing, for each data point to be processed, a prediction of membership or non-membership in the training data of the target classification model and preferably an associated confidence score.

[0080] For example, and as described in more detail below, two distinct and complementary membership inference models are developed, a first "white box" type model, the target model being considered known, and a second "black box" type model, the target model being considered unknown.

[0081] More generally, the number P of membership inference models is any number greater than or equal to 2.

[0082] Finally, the processor 4 includes a machine learning module 28, which, on a second subset of control models, provides parameters of one or more decision model(s) 30 taking as input said membership or non-membership predictions and the associated confidence scores provided by the P distinct membership inference models. The decision module provides as output a consolidated membership or non-membership prediction.

[0083] In one embodiment, the decision models 30 include one or more classifiers chosen from models of: logistic regression, random forest, adaptive amplification, gradient amplification, naive Bayesian model. Of course, this list is not exhaustive; any statistical classification method is applicable.

[0084] When several decision models are implemented, a determination module 32 is also implemented by combining the results of the decision models 30. For example, the combination is performed by majority vote to obtain a final prediction, also called the final decision. Thus, a final decision is obtained for each data point to be processed regarding whether or not the data point to be processed belongs to the training data of the target model.

[0085] Of course, after machine learning of the membership inference models 26i..26P, and of the decision model(s) 30, each of these models becomes an executable machine learning trained model to implement the task for which it was trained.

[0086] Thus, in an operational phase subsequent to the learning phase, the target model 8, the membership inference models 26i..26P, the decision model(s) 30 and the determination module 32 are executed on a data to be processed to determine the membership or non-membership of this data in the training data of the target model 6.

[0087] In one embodiment, modules 20, 22, 26, 24, 28, 30, 32 are implemented in the form of software instructions forming a computer program, which, when executed by a programmable electronic device, implements a method for determining membership in the training data according to the invention.

[0088] In an alternative not shown, modules 22, 24, 26, 28, 30, 32 are each implemented as programmable logic components, such as FPGAs (Field Programmable Gate Arrays), microprocessors, GPGPUs (General-Purpose Processing on Graphics Processing) components, or dedicated integrated circuits, such as ASICs (Application-Specific Integrated Circuits).

[0089] The computer program comprising software instructions is further capable of being stored on a non-transient, computer-readable information storage medium. This computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. By way of example, this medium is an optical disc, a magneto-optical disc, a ROM, a RAM, any type of non-volatile memory (e.g., EPROM, EEPROM, FLASH, NVRAM), a magnetic card, or an optical card.

[0090] Fig. 2 is a synoptic diagram of the main steps of a membership determination process in the learning phase, according to an embodiment in which the number P of membership inference models is equal to 2.

[0091] The target model and the dataset to be processed are provided as input.

[0092] The method includes a step 40 of generating N partitions of the set of data to be processed.

[0093] As shown more explicitly in [Fig.3], for each partition Part; among the N partitions PartiPart2j...PartN, a first subset of data SI includes instances intended for training, in particular for training control models, and a second subset of data S2 includes data intended for testing and validation.

[0094] The validation data are used to choose hyperparameters of the control model and to verify the convergence of this model.

[0095] The test data are not used in the training phase and serve to evaluate the performance of the model.

[0096] In one embodiment, the first subset of data SI, used for training; contains more data than the second subset of data S2, used for testing or validation, preferably the first subset of data SI contains at least 60% of the data.

[0097] In another embodiment, the data subsets comprise the same number of data.

[0098] For example, for the generation of a given partition, each input data is assigned, for example randomly, to the first subset of data SI or to the second subset of data S2.

[0099] In one embodiment, N / 2 partitions are generated randomly, and the other N / 2 are generated by complementarity, by reversing the allocation of each data, so as to ensure that each data is allocated N / 2 times to the first subset of data SI (i.e. for training) and N / 2 times to the second subset of data S2.

[0100] In a preferred embodiment, for each data point, N / 2 partitions are randomly chosen in which the input data is assigned to the first data subset S1 (i.e., for training), and, by complementarity, the data is assigned to the second data subset S2 in the remaining N / 2 partitions. In this variant, the assignment to one or the other of the subsets in each partition is done on a per-data basis.

[0101] A set of N partitions such that each data assigned N / 2 times to the first subset S1 and N / 2 times to the second subset S2 is said to be a balanced set.

[0102] The process then includes a step 42 of calculating by machine learning N reference models of the target model, i.e. which provide results substantially identical to those provided by the target model on a subset of training data.

[0103] Each control model is trained on a separate partition of the dataset to be processed, and more specifically on the first subset of data of the partition.

[0104] At the end of step 42, N distinct control models are obtained and stored.

[0105] In one embodiment, step 42 performs a machine learning calculation of a first subset of reference models, on a balanced set of NI partitions, and a second subset of reference models, on a balanced set of N2 partitions, with N=N1+N2.

[0106] The process then comprises, in one embodiment, machine learning 44 of a first membership inference model, with knowledge of the parameters of the target model, and machine learning 46 of a second membership inference model, without knowledge of the target model.

[0107] Each of the learning steps 44 and 46 implements a first subset of control models.

[0108] For example, for N=288 calculated control models, the first subset comprises N1=256 control models, and a second subset of N2=32 control models, each of the first and second subsets of control models being learned on a balanced subset of training data.

[0109] The first subset of control models is used for training membership inference models.

[0110] The second subset of control models is used subsequently for training a decision model.

[0111] By way of non-limiting example, step 44 implements the learning of a first membership inference model, which implements a calculation of characteristic influence values ​​of each data to be processed, using the previously calculated reference models.

[0112] The calculation of influence functions is described in the article "Membership Inference Attack Using Self Influence Functions" by G. Cohen and R. Giryes.

[0113] In one embodiment during step 44:

[0114] -for each control model of the first subset of control models and each instance of the data to be processed, the influence of the instance considered with respect to the instances of its class given the target model is calculated;

[0115] -for each control model and each instance, characteristic values ​​are calculated;

[0116] - a machine learning of a decision model, for example by logistic regression, of membership or non-membership in the training data, the decision being made on the calculated characteristic values, in knowledge of the actual membership of each instance in the subset of training data of each control model.

[0117] For example, in one embodiment, the calculated characteristic values ​​include, for each instance and each control model, one or more of the following characteristic values: the self-influence value, the average influence of the instance on the data of its class, the average influence of the data of its class on the instance under consideration, the opposite of the output value of the control model for the instance's class, the classification loss (in English, "hinge loss").

[0118] In a classic way in the field of artificial intelligence, the term "logit" designates an output vector of a classification model trained by machine learning, this vector having a size equal to the number of classes, each component of this vector corresponding to one of the classes and having a value, called the output value above, for said class.

[0119] In a classic manner in the field of artificial intelligence, the classification loss, or "hinge loss", for an instance of a class, is equal to the output value for its class less the largest value among the other output values.

[0120] The first membership inference model thus trained provides as output, for each data item to be processed Ei, a prediction Prédl(Ei) of membership or non- belonging of the data Ei to the training data of the target classification model and an associated confidence score ScoreH.

[0121] By way of non-limiting example, step 46 implements a second membership inference model which implements a likelihood ratio of the classification loss function (in English, "hinge loss").

[0122] An example of such a membership inference model is described in the article "Membership inference attacks from first principles" by N. Carlini et al., published in IEEE Symposium on Security and Privacy, 2022. In one embodiment, step 46 comprises substeps of:

[0123] -calculation of the classification loss value ("hinge loss") for each control model and each instance;

[0124] - determination, for each instance, of the parameters of two Gaussians, the parameters being respectively the median and the standard deviation, and the Gaussians being respectively:

[0125] a first Gaussian representative of the distribution of the classification loss value when the instance was used to train the control model;

[0126] a second Gaussian representative of the distribution of the classification loss value when the instance was not used to train the control model.

[0127] -for each instance, and each control model, determination of membership or non-membership based on the Gaussians, including a calculation of the ratio between the membership likelihood score using the first Gaussian and the membership likelihood score using the second Gaussian;

[0128] -and calculation of an average attack score on the control models, this score being analogous to a learning fidelity value, allowing a confidence score to be obtained for the second membership inference model for the instance considered.

[0129] This second membership inference model thus trained provides as output, for each data to be processed Ei, a prediction Préd2(Ei) of membership or non-membership of the data Ei in the training data of the target classification model, an associated confidence score Score2 i.

[0130] Moreover, in this embodiment, the second membership inference model also provides a training accuracy value, which is also considered as another confidence score value associated with the application of this second inference model.

[0131] The process then includes a step 48 of learning a decision model.

[0132] This learning process takes as input, for each data point to be processed, and for each control model in the second subset of control models, the membership prediction obtained by the control model. As already indicated above, the control models in the second subset of control models are preferably control models that were not used for training membership inference models.

[0133] In the embodiment described with reference to [Fig.2], the learning also takes as input the membership score provided by each of the membership inference models.

[0134] Moreover, for each control model, the membership or non-membership of the data to be processed in the first set of data (i.e. training data) used for training the control model is known, by construction of the control model.

[0135] It is then possible to train a decision model, for example a binary classifier, which provides as output a prediction of membership or non-membership which is called consolidated prediction, and optionally, an associated confidence score.

[0136] The decision thus obtained is more faithful than the respective predictions of each of the membership inference models, a fortiori when the predictions are combined taking into account their respective confidence scores.

[0137] In the case where only one binary classifier is trained in step 48, the consolidated prediction of membership or non-membership provided by this classifier constitutes a final decision.

[0138] In the case where several distinct binary classifiers are trained in step 48, the process also includes a step 50 of determining membership or non-membership (i.e. final decision) by combining the consolidated predictions of the binary classifiers.

[0139] For example, when the number of binary classifiers is odd, step 50 implements a majority vote: the majority consolidated prediction is retained as the final decision on whether or not to include the target model's training data.

[0140] In another embodiment, step 50 implements a learning of weights to be assigned to the classifiers used.

[0141] Of course, other methods of different combinations are conceivable for a man of the art.

[0142] Figure 4 is a synoptic diagram of the main steps in a determination process of belonging in the operational phase, after implementation of the learning described above with reference to [Fig.2], according to an embodiment mode.

[0143] For a data to be processed ET, for example an image, the process includes the application 60 of the target model, the application 62, 64 of the first and second membership inference models, then the application 66 of the previously trained decision models and the application, where appropriate, of the determination step 68 to obtain a consolidated prediction, and a final decision on whether or not the data to be processed belongs to the training data of the target model.

[0144] The embodiment described with reference to Figures 2 and 4 involves the implementation of two distinct membership inference models.

[0145] Of course, the described method can be easily generalized to any number of distinct membership inference models, for example three, four, or more, each membership inference model being learned on reference models and providing a prediction of membership or non-membership in the training data and optionally, one or more associated confidence scores. Machine learning on a second subset of reference models, using parameters of at least one decision model taking as input the membership or non-membership predictions, is then performed on the predictions obtained by the plurality of membership inference models, and where applicable, the associated confidence scores.

Claims

Claims

1. Method for determining membership in the training data used for training a data classification model by machine learning, called the target model (8), the method being implemented by a calculation processor, and comprising, in a learning phase, implemented on a set (10) of data to be processed, steps of: - generation (40) of a number N greater than 2 of distinct partitions (Parti,.. .,PartN) of the set of data to be processed into a first (S 11 ,..,S1N) and a second (S2b...,S2N) subset of data, - calculation (42) by machine learning of N witness models (16i ,...,16N), each witness model (16i,...,16N) having the same structure as said target model (8), the calculation (42) comprising the learning of the parameters of each witness model from a first subset (S 1 b..,S 1N) of data from one of the partitions, to provide as output a classification substantially identical to that provided by the target model (8); -machine learning (44, 46) on a first subset of witness models of at least two distinct membership inference models (26b..., 26P) each providing, for each data to be processed, a prediction of membership or non-membership to the training data of the target model, -machine learning, on a second subset of witness models, of the parameters of at least one decision model (48) taking as input said predictions of membership or non-membership and providing as output a consolidated prediction of membership or non-membership.

2. Method according to claim 1, in which at least one of the membership inference models provides, for each data to be processed, a confidence score associated with the prediction of membership or non-membership in the training data of the target model, and in which the machine learning of said at least one decision model (48) takes said confidence scores as input.

3. Method according to claim 2, in which each distinct membership inference model provides for each data to be processed, a confidence score associated with the prediction of membership or non-membership in the training data of the model target, and wherein machine learning, on a second subset of witness models, the parameters of at least one decision model (48) takes as input said membership or non-membership predictions and the associated confidence scores provided by each distinct membership inference model.

4. Method according to one of claims 1 to 3, further comprising an operational phase comprising, for at least one data item to be processed, steps of: - implementing each of said membership inference models (62, 64) on said data item to be processed to obtain membership or non-membership predictions and the associated confidence scores; - determining (66, 68) a consolidated membership or non-membership prediction of said data item to be processed to the learning data by applying said decision model to the membership or non-membership predictions and the associated confidence scores.

5. A method according to any one of claims 1 to 4, wherein a first membership inference model using knowledge of the parameters of the target model, and a second membership inference model without using the parameters of the target model are implemented.

6. A method according to any one of claims 1 to 5, wherein a plurality of decision models are implemented among models of: logistic regression, random forest, adaptive boosting, gradient boosting, naive Bayesian model.

7. Method according to claim 6, further comprising a step of determining membership or non-membership to obtain a final prediction of membership or non-membership by combining (50) the results of the decision models.

8. The method of claim 7, wherein the combining (50) of the results is performed by majority voting or weighted majority voting.

9. A computer program comprising software instructions which, when executed by a programmable electronic device, implement a method of determining of membership in the training data according to claims 1 to 8.

10. Device for determining membership in the training data used for training a data classification model by machine learning, called the target model (8), the device (2) comprising a calculation processor (4), configured, in a learning phase, to implement on a set (10) of data to be processed: - a module (20) for generating a number N greater than 2 of distinct partitions (Parti,...,PartN) of the set of data to be processed into a first (SIb..,S 1N) and a second (S2i,...,S2N) subsets of data, - a module (22) for calculating by machine learning N control models (16i,...,16N), each control model (16i,...,16N) having the same structure as said target model (8), the calculation comprising learning the parameters of each control model from the first subset (16i,...,16N) of data from one of the partitions, to provide as output a classification substantially identical to that provided by the target model (8); - a machine learning module (24) on a first subset of witness models of at least two distinct membership inference models each providing, for each data to be processed, a prediction of membership or non-membership to the training data of the target model, - a machine learning module (30), on a second subset of witness models, of the parameters of at least one decision model taking as input said predictions of membership or non-membership and providing as output a consolidated prediction of membership or non-membership.