Calculation device, calculation method, and calculation program
The calculation device addresses the challenge of assessing privacy risk in Bayesian NNs by creating an adjacent dataset, training, and determining the original dataset based on NN outputs, effectively quantifying their susceptibility to data inference.
Patent Information
- Application Number
- JP2023553918
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-18
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2041-10-18
AI Technical Summary
Conventional methods struggle to calculate the privacy risk of Bayesian Neural Networks (NNs) due to their output of posterior distributions, unlike deterministic NNs, which existing techniques target.
A calculation device and method that creates an adjacent dataset, trains a Bayesian NN on this dataset, determines the original dataset based on the NN's output, and calculates privacy risk using false positive and negative rates.
Enables the calculation of privacy risk for Bayesian NNs, allowing for evaluation of their vulnerability to data inference attacks.
Smart Images

Figure 0007713143000002 
Figure 0007713143000003 
Figure 0007713143000004
Abstract
Description
Technical Field
[0001] The present invention relates to a calculation device, a calculation method, and a calculation program.
Background Art
[0002] It has been pointed out that machine learning techniques typified by Deep Neural Network (DNN) have a privacy risk. This is because the learned model has a characteristic of easily memorizing teacher data.
[0003] Specifically, it has been shown that it is possible to estimate whether specific data was included in the teacher data from the output of the learned model. In particular, when dealing with data that users do not want others to know, such as medical data and web browsing history, it is necessary to consider privacy risks.
[0004] On the other hand, a method for calculating privacy risk based on the degree of success of an attack for identifying whether certain data is included in a dataset is known (see, for example, Non-Patent Document 1 and Non-Patent Document 2).
Prior Art Documents
Non-Patent Documents
[0005]
Non-Patent Document 1
Non-Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0006] However, the conventional techniques have a problem that it is difficult to calculate the privacy risk of Bayesian NNs.
[0007] The methods described in Non-Patent Document 1 and Non-Patent Document 2 target models using deterministic NNs that output one prediction value for an input.
[0008] On the other hand, since a Bayesian NN outputs the posterior distribution of prediction values or values sampled from the posterior distribution, the conventional methods cannot be applied.
Means for Solving the Problems
[0009] In order to solve the above-described problems and achieve the object, a calculation device includes: a creation unit that creates a second data set adjacent to the first data set based on the first data set; a learning unit that performs learning of a Bayesian neural network (NN) using either the first data set or the second data set as teacher data; a determination unit that determines whether the teacher data used for learning the Bayesian NN is the first data set or the second data set based on the output of the Bayesian NN learned by the learning unit; and a calculation unit that calculates a privacy risk based on the determination result by the determination unit.
Advantages of the Invention
[0010] According to the present invention, the privacy risk of a Bayesian NN can be calculated.
Brief Description of Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0012] Hereinafter, embodiments of a calculation device, a calculation method, and a calculation program according to the present application will be described in detail with reference to the drawings. Note that the present invention is not limited to the embodiments described below.
[0013] In the first embodiment, the privacy risk related to Bayesian NN (neural network) is particularly calculated.
[0014] Here, Bayesian NN is a machine learning technique based on NN. Parameters such as weights and biases in Bayesian NN are treated as following a probability distribution. And the posterior distribution of each parameter is obtained by Bayesian estimation.
[0015] Using FIG. 1, a method of calculating privacy risk by the calculation device in the first embodiment will be described. FIG. 1 is a diagram for explaining a method of calculating privacy risk.
[0016] As shown in FIG. 1, first, the calculation device creates an adjacent dataset D' from the dataset D (step S1).
[0017] For example, when the dataset D contains a plurality of data items each represented in the form of (x, y), the calculation device creates a dataset D' by adding the data (x', y') to the dataset D.
[0018] Then, the calculation device randomly selects either the dataset D or the dataset D' (step S2).
[0019] Next, the calculation device uses the selected dataset as training data to train the model (step S3). For example, the model is a Bayesian NN.
[0020] Here, the calculation device determines whether the dataset used as the training data is the dataset D or the dataset D' based on the output of the trained model (step S4).
[0021] Furthermore, the calculation device calculates the privacy risk based on the determination result (step S5). For example, it can be said that the higher the determination accuracy in step S4, the easier it is for the attack to succeed, and the greater the privacy risk.
[0022] For example, a high determination accuracy means that it is easy to infer from the output which dataset was used for training, and furthermore, it is easy to identify that the data (x', y') was used for training.
[0023] Note that the calculation device performs the selection of the dataset multiple times in step S2, and each time a dataset is selected, it executes the training in step S3 and the determination in step S4.
[0024] At this time, even if the selected datasets are the same, the trained Bayesian NNs are not necessarily the same.
[0025] Hereinafter, together with the configuration of the calculation device in the embodiment, the details of each process described with reference to FIG. 1 will be described.
[0026] [Configuration of the First Embodiment] With reference to FIG. 2, the configuration of the calculation device according to the first embodiment will be described. FIG. 2 is a diagram showing a configuration example of the calculation device according to the first embodiment. The calculation device 10 receives an input of a data set and calculates the privacy risk regarding the Bayesian NN.
[0027] As shown in FIG. 2, the calculation device 10 includes a communication unit 11, an input unit 12, an output unit 13, a storage unit 14, and a control unit 15.
[0028] The communication unit 11 performs data communication with other devices via a network. For example, the communication unit 11 is a NIC (Network Interface Card).
[0029] The input unit 12 receives an input of data from a user. The input unit 12 is, for example, an input device such as a mouse or a keyboard, or an interface connected to the input device.
[0030] The output unit 13 outputs data by, for example, displaying on a screen. The output unit 13 is, for example, an output device such as a display and a speaker, or an interface connected to the output device.
[0031] The storage unit 14 is a storage device such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), or an optical disk. Note that the storage unit 14 may be a semiconductor memory capable of rewriting data, such as a RAM (Random Access Memory), a flash memory, or an NVSRAM (Non Volatile Static Random Access Memory).
[0032] The storage unit 14 stores an OS (Operating System) and various programs executed by the calculation device 10. The storage unit 14 stores model information 141 and learning data 142.
[0033] The model information 141 is, for example, the hyperparameters (number of layers, number of units, activation function, etc.) of a model using Bayesian NN. More specifically, the model information 141 may be parameters such as the mean, variance, etc. for specifying the probability distribution followed by the weights and biases.
[0034] Also, the learning data 142 is data for training the Bayesian NN. For example, the learning data 142 is the dataset D.
[0035] For example, the dataset D may have data combining labels and features as elements.
[0036] The control unit 15 controls the entire calculation device 10. The control unit 15 is, for example, an electronic circuit such as a CPU (Central Processing Unit), MPU (Micro Processing Unit), GPU (Graphics Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array).
[0037] Also, the control unit 15 has an internal memory for storing programs and control data that define various processing procedures, and executes each process using the internal memory.
[0038] The control unit 15 functions as various processing units when various programs operate. For example, the control unit 15 has a creation unit 151, a learning unit 152, a determination unit 153, and a calculation unit 154.
[0039] The creation unit 151 creates a dataset D' adjacent to the dataset D based on the dataset D. The dataset D is an example of a first dataset. Also, the dataset D' is an example of a second dataset.
[0040] As described with reference to FIG. 1, the creation unit 151 creates a data set D' by adding data (x', y') to the data set D.
[0041] In this case, the data set D and the data set D' can be said to be two data sets that differ only in one element.
[0042] For example, the data (x', y') is selected from the data included in the data set D. The data (x', y') may be randomly selected.
[0043] Also, for example, the data (x', y') may be data that has a greater impact when the data set D' is used as teacher data. The magnitude of the impact increases as the loss of the model when learning is performed using the data set D' as teacher data becomes larger.
[0044] Also, the data (x', y') may be selected according to what kind of privacy risk is to be calculated.
[0045] Also, the creation unit 151 may create the data set D' by adding noise to the data (x', y') and then adding it to the data set D.
[0046] The learning unit 152 performs learning of a Bayesian neural network (NN) using either the data set D or the data set D' as teacher data.
[0047] For example, the learning unit 152 randomly selects either the data set D or the data set D', and uses the selected data set as teacher data to perform model learning.
[0048] For example, the model is an unlearned Bayesian NN constructed from the model information 141. Each time the learning unit 152 selects a data set, it can construct a model from the model information 141 and perform learning.
[0049] The learning unit 152 can perform learning by using known machine learning methods. Further, the learning unit 152 may perform learning by using a privacy-preserving machine learning method (for example, a learning method that guarantees differential privacy).
[0050] The determination unit 153 determines whether the teacher data used for learning the Bayesian NN is the data set D or the data set D' based on the output of the Bayesian NN learned by the learning unit 152. For example, the determination unit 153 makes a determination based on the output obtained by inputting one sample to the Bayesian NN once or multiple times, or the output obtained by inputting each of a plurality of samples to the Bayesian NN once or multiple times.
[0051] For example, the determination unit 153 makes a determination by using the output when the data (x', y') is input to the learned Bayesian NN. Further, the determination unit 153 may make a determination by using the output when the data (x', y') with noise added thereto is input to the learned Bayesian NN.
[0052] The determination unit 153 can determine whether the teacher data used for learning the Bayesian NN is the data set D or the data set D' based on the integrated information obtained by inputting one sample to the Bayesian NN learned by the learning unit 152 a plurality of times, or by inputting each of a plurality of samples to the Bayesian NN one or more times. Note that the determination unit 153 may make a determination based on one output obtained by inputting one sample to the Bayesian NN only once.
[0053] For example, the determination unit 153 determines whether the teacher data for each of the outputs obtained by inputting a plurality of samples to the learned Bayesian NN is the data set D or the data set D'. Thereby, the determination unit 153 can obtain a plurality of determination results.
[0054] For example, when all of the plurality of determination results indicate that the teacher data is the data set D', the determination unit 153 finally determines that the teacher data is the data set D'.
[0055] Also, for example, when one or more of the plurality of determination results indicate that the teacher data is the data set D', the determination unit 153 finally determines that the teacher data is the data set D'.
[0056] Also, for example, when the number of determination results indicating that the teacher data is the data set D' is larger than the number of determination results indicating that the teacher data is the data set D among the plurality of determination results, the determination unit 153 finally determines that the teacher data is the data set D'.
[0057] Here, the output of the Bayesian NN is determined according to a predetermined posterior distribution. The Bayesian NN can output statistical values such as the mean of the posterior distribution.
[0058] When the Bayesian NN outputs a statistical value of the posterior distribution, the determination unit 153 determines whether the teacher data used for learning the Bayesian NN is the data set D or the data set D' based on the statistical value.
[0059] Also, the Bayesian NN may output a plurality of predicted values sampled from the posterior distribution.
[0060] When the Bayesian NN outputs a plurality of predicted values sampled from the posterior distribution, the determination unit 153 determines whether the teacher data used for learning the Bayesian NN is the data set D or the data set D' based on the statistical value regarding the plurality of predicted values.
[0061] In any case, the type of the statistical value may be one or plural. The type of the statistical value is, for example, the mean, the maximum value, the minimum value, the value smaller than the i-th value (where i is an integer from 1 to the number of samples) among the predicted values, and the like.
[0062] Using FIG. 3, a method for determining a data set using the statistical value by the determination unit 153 will be described. FIG. 3 is a diagram for explaining the method for determining a data set.
[0063] Note that the information 1f and the information 2f each correspond to a predetermined type of statistical value. For example, the information 1f may be an average and the information 2f may be a maximum value.
[0064] The determination unit 153 determines whether the teacher data used for learning the Bayesian NN is the data set D or the data set D' based on whether the statistical value is greater than or equal to a threshold value.
[0065] For example, when all types of statistical values are greater than or equal to the threshold value, the determination unit 153 determines that the teacher data is the data set D'. This determination method corresponds to type A in FIG. 3.
[0066] As shown in FIG. 3, in the determination method of type A, the region determined to be the data set D' is the overlapping portion of the region where the information 1f is greater than or equal to the threshold value and the region where the information 2f is greater than or equal to the threshold value.
[0067] Also, for example, when any type of statistical value is greater than or equal to the threshold value, the determination unit 153 determines that the teacher data is the data set D'. This determination method corresponds to type B in FIG. 3.
[0068] As shown in FIG. 3, in the determination method of type B, the region determined to be the data set D' is both the region where the information 1f is greater than or equal to the threshold value and the region where the information 2f is greater than or equal to the threshold value.
[0069] Also, not limited to the regions in type A and type B, when there exists a point determined from each information in a predetermined region in a plane (in the case of three or more pieces of information, a space) as shown in FIG. 3, the determination unit 153 can determine that the teacher data is the data set D'.
[0070] The information used for determination by the threshold is desirably a value that tends to increase when the teacher data is the data set D'. Statistical values such as the average, maximum value, and minimum value have such a tendency.
[0071] On the other hand, the standard deviation tends to decrease when the teacher data is the data set D'. Therefore, the determination unit 153 can use, instead of the standard deviation itself, the reciprocal of the standard deviation or a value obtained by inverting the sign of the standard deviation as information for determination.
[0072] Note that when the Bayesian NN outputs a predetermined statistical value without outputting a plurality of prediction values, the determination unit 153 makes a determination using the statistical value.
[0073] For example, when the Bayesian NN outputs only the average and the standard deviation, the determination unit 153 cannot make a determination using statistical values other than the average and the standard deviation.
[0074] This makes it possible to evaluate how the privacy risk changes depending on how the output of the Bayesian NN is disclosed.
[0075] The calculation unit 154 calculates the privacy risk based on the determination result by the determination unit 153.
[0076] Here, it is assumed that the learning by the learning unit 152 and the determination by the determination unit 153 are performed multiple times.
[0077] When the actual teacher data is the data set D, the ratio at which the determination unit 153 determines that the teacher data is the data set D' is defined as the false positive rate (FPR).
[0078] On the other hand, when the actual teacher data is the data set D', the ratio at which the determination unit 153 determines that the teacher data is the data set D is defined as the false negative rate (FNR).
[0079] At this time, the calculation unit 154 can calculate the privacy risk by the formula (1).
[0080] [Number]
[0081] δ is a sufficiently small constant (for example, 10 -5 ). The determination unit 153 may use a threshold value such that the privacy risk calculated from the formula (1) becomes large. Further, the calculation unit 154 may calculate the privacy risk in consideration of the confidence interval.
[0082] Note that the calculation unit 154 may calculate the privacy risk by a method based on the ratio of probabilities and a method using a predetermined test method in addition to the method using the formula (1).
[0083] (Example) The calculation device 10 can compare the privacy risks of the deterministic NN and the Bayesian NN by, for example, the following method. Thereby, it becomes possible to evaluate the degree of increase in the privacy risk when the Bayesian NN is introduced.
[0084] First, the calculation device 10 uses a CNN (Convolutional Neural Network) to which Dropout is applied as the NN. Further, the calculation device 10 performs learning of the CNN by DP (Differentially Private)-SGD (Stochastic Gradient Descent).
[0085] Then, the calculation device 10 calculates the privacy risk of the Bayesian NN obtained by applying MC dropout to the CNN by the method of the embodiment.
[0086] Next, the calculation device 10 calculates the privacy risk of the CNN as a deterministic NN by a conventional method (for example, the method described in Non-Patent Document 1 or Non-Patent Document 2).
[0087] The calculation device 10 compares the privacy risk of the Bayesian NN with the privacy risk of the CNN as a deterministic NN.
[0088] [Processing of the First Embodiment] Using FIG. 4, the processing flow of the calculation device 10 will be described. FIG. 4 is a flowchart showing the processing flow of the calculation device according to the first embodiment.
[0089] As shown in FIG. 4, first, the calculation device 10 creates a data set D' adjacent to the learning data set D (step S101). For example, the calculation device 10 creates the data set D' by adding data (x', y') to the data set D.
[0090] Next, the calculation device 10 randomly selects either the data set D or the data set D' (step S102). The calculation device 10 makes the selection multiple times.
[0091] The calculation device 10 performs model learning using the selected data set (step S103). The calculation device 10 may perform learning by a privacy-preserving machine learning method.
[0092] The calculation device 10 determines which of the data set D and the data set D' was used for learning from the learning result (step S104). For example, the calculation device 10 makes the determination using statistical values related to the output of the model.
[0093] Until the end condition is satisfied (step S105, No), the calculation device 10 repeats steps S102 to S104. For example, the end condition is that steps S102 to S104 have been repeated a certain number of times.
[0094] On the other hand, when the termination condition is satisfied (step S105, Yes), the calculation device 10 proceeds to step S106.
[0095] The calculation device 10 calculates the privacy risk based on the determination result (step S106). For example, when the calculation device 10 determines that the teacher data is the data set D´ as positive, the privacy risk can be calculated from the FPR and FNR.
[0096] [Effects of the First Embodiment] As described so far, the creation unit 151 creates a second data set adjacent to the first data set based on the first data set. The learning unit 152 performs learning of the Bayesian neural network (NN) using either the first data set or the second data set as teacher data. The determination unit 153 determines whether the teacher data used for the learning of the Bayesian NN is the first data set or the second data set based on the output of the Bayesian NN learned by the learning unit 152. The calculation unit 154 calculates the privacy risk based on the determination result by the determination unit 153.
[0097] In this way, the calculation device 10 determines the data set of the teacher data based on the output of the Bayesian NN, and calculates the privacy risk from the determination result. As a result, according to the present embodiment, the privacy risk of the Bayesian NN can be calculated.
[0098] The determination unit 153 determines whether the teacher data used for the learning of the Bayesian NN is the first data set or the second data set based on the integrated information obtained by inputting one sample to the Bayesian NN learned by the learning unit 152 a plurality of times, or by inputting each of a plurality of samples to the Bayesian NN one or more times. In this way, the calculation device 10 can perform a statistical determination using, for example, FPR and FNR by using a plurality of outputs.
[0099] When the Bayesian NN outputs statistical values of the posterior distribution, the determination unit 153 determines, based on the statistical values, whether the teacher data used for learning the Bayesian NN is the first data set or the second data set. In this way, the calculation device 10 can easily make a determination using the output of the Bayesian NN.
[0100] When the Bayesian NN outputs a plurality of predicted values sampled from the posterior distribution, the determination unit 153 determines, based on the statistical values related to the plurality of predicted values, whether the teacher data used for learning the Bayesian NN is the first data set or the second data set. In this way, the calculation device 10 can make a determination using arbitrary statistical values by utilizing the output of the Bayesian NN.
[0101] The determination unit 153 determines whether the teacher data used for learning the Bayesian NN is the first data set or the second data set based on whether the statistical value is greater than or equal to a threshold value. In this way, the calculation device 10 can easily make a determination based on the threshold value.
[0102] [System configuration, etc.] Moreover, each component of each illustrated device is conceptually functional and does not necessarily have to be physically configured as shown in the figure. That is, the specific form of the distribution and integration of each device is not limited to that shown in the figure, and all or part of it can be functionally or physically distributed or integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU (Central Processing Unit) and a program analyzed and executed by the CPU, or can be realized as hardware by wired logic. Note that the program may be executed not only by the CPU but also by other processors such as a GPU.
[0103] Also, among the various processes described in this embodiment, all or part of the processes described as being automatically performed can be manually performed, or all or part of the processes described as being manually performed can be automatically performed by a known method. In addition, regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed unless otherwise specified.
[0104] [Program] As an embodiment, the calculation device 10 can be implemented by installing a calculation program that executes the above-described calculation process as package software or online software on a desired computer. For example, by causing the information processing device to execute the above-described calculation program, the information processing device can function as the calculation device 10. The information processing device mentioned here includes desktop or notebook personal computers. In addition, other information processing devices include mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone System), and further slate terminals such as PDAs (Personal Digital Assistants) are included in this category.
[0105] Also, the calculation device 10 can be implemented as a calculation server device that uses the terminal device used by the user as a client and provides a service related to the above-described calculation process to the client. For example, the calculation server device is implemented as a server device that provides a calculation service that takes a data set as an input and outputs the privacy risk of the Bayesian NN. In this case, the calculation server device may be implemented as a Web server, or may be implemented as a cloud that provides a service related to the above-described calculation process through outsourcing.
[0106] FIG. 5 is a diagram showing an example of a computer that executes a calculation program. The computer 1000 includes, for example, a memory 1010 and a CPU 1020. The computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0107] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012. The ROM 1011 stores, for example, a boot program such as BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.
[0108] The hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the program that defines each process of the calculation device 10 is implemented as a program module 1093 in which computer-executable code is described. The program module 1093 is stored, for example, in the hard disk drive 1090. For example, a program module 1093 for executing the same processing as the functional configuration in the calculation device 10 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).
[0109] Also, the setting data used in the processing of the above-described embodiments is stored, for example, in the memory 1010 or the hard disk drive 1090 as program data 1094. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed, and executes the processing of the above-described embodiments.
[0110] Note that the program module 1093 and the program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and the program data 1094 may be stored in another computer connected via a network (LAN (Local Area Network), WAN (Wide Area Network), etc.). Then, the program module 1093 and the program data 1094 may be read by the CPU 1020 from another computer via the network interface 1070.
Explanation of Reference Numerals
[0111] 10 Calculation device 11 Communication unit 12 Input unit 13 Output unit 14 Storage unit 15 Control unit 141 Model information 142 Learning data 151 Creation unit 152 Learning unit 153 Determination unit 154 Calculation unit
Claims
1. A creation unit that creates a second data set adjacent to the first data set based on the first data set; A learning unit that performs learning of a Bayesian neural network (NN) using either the first data set or the second data set as teacher data; A determination unit that determines whether the teacher data used for learning the Bayesian NN is the first data set or the second data set based on a value that decreases as the standard deviation, which is a statistical value output by the Bayesian NN learned by the learning unit, increases; A calculation unit that calculates a privacy risk based on the determination result by the determination unit; A calculation device, characterized by comprising:
2. The determination unit according to claim 1, wherein the determination unit determines whether the teacher data used for learning the Bayesian NN is the first data set or the second data set based on information obtained by integrating a plurality of outputs obtained by inputting one sample to the Bayesian NN learned by the learning unit a plurality of times or by inputting each of a plurality of samples to the Bayesian NN one or more times.
3. When the Bayesian NN outputs a standard deviation that is a statistical value of the posterior distribution, the determination unit determines whether the teacher data used for learning the Bayesian NN is the first data set or the second data set based on a value that decreases as the standard deviation increases. The calculation device according to claim 1 or 2, characterized by:
4. When the Bayesian NN outputs a plurality of predicted values sampled from the posterior distribution, the determination unit determines whether the teacher data used for learning the Bayesian NN is the first data set or the second data set based on a statistical value related to the plurality of predicted values. The calculation device according to claim 1 or 2, characterized by:
5. The determination unit according to claim 3 or 4, wherein the determination unit determines whether the teacher data used for learning the Bayesian NN is the first data set or the second data set based on whether the statistical value is greater than or equal to a threshold value.
6. A calculation method executed by a calculation device, A creation step of creating a second data set adjacent to the first data set based on the first data set; A learning step of performing learning of the Bayesian NN using either the first dataset or the second dataset as teacher data; A determination step of determining whether the teacher data used for the learning of the Bayesian NN is the first dataset or the second dataset based on a value that becomes smaller as the standard deviation, which is a statistical value output by the Bayesian NN learned in the learning step, becomes larger; A calculation step of calculating a privacy risk based on the determination result in the determination step; A calculation method characterized by including the above.
7. A calculation program for causing a computer to function as the calculation device according to any one of claims 1 to 5.
Citation Information
Patent Citations
Analysis device, machine learning device, analysis system, analysis method, and recording medium
WO2020090821A1