Risk Evaluation Device for Membership Inference Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing models comprising multiple partial models face challenges in effectively evaluating the risk of information leakage, particularly in membership inference attacks where training data is estimated from inference results.
Innovation Solution
A risk evaluation device and method that acquire target data, calculate confidence scores for each partial model, and evaluate the possibility of target data being included in a training set, with adjustments for confidence scores indicating zero elements in a class to indicate one or more elements, thereby assessing and mitigating information leakage risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If confidence scores are calculated for each partial model to evaluate information leakage risk, then measurement precision of risk evaluation is improved, but device complexity increases due to multiple partial models and confidence score calculations
Solution Approach 1:
The patent divides the evaluation process into multiple partial models, each handling specific aspects of risk assessment. By segmenting the overall evaluation into manageable partial models with individual confidence scores, the system achieves comprehensive risk measurement while maintaining structured complexity that can be systematically managed and interpreted.
Solution Approach 2:
The patent creates a universal evaluation framework where multiple partial models serve the common function of risk assessment. Each partial model contributes to the overall confidence score calculation, allowing the system to evaluate information leakage risk across different scenarios and data types using a unified multi-model approach.
2Loss of information
If confidence scores indicating zero elements are rewritten to indicate one or more elements, then loss of information is reduced by preventing complete exclusion of classes, but measurement precision is reduced due to intentional modification of calculated values
Solution Approach 1:
The patent applies preliminary anti-action by pre-modifying confidence scores that would otherwise indicate zero elements. This preventive measure ensures that no class is completely excluded from consideration, maintaining information completeness while being applied systematically before final risk evaluation decisions are made.
Solution Approach 2:
The patent changes the parameter values of confidence scores from their calculated state to a modified state where zero values are transformed to indicate one or more elements. This parameter change balances the need to preserve information about all possible classes while acknowledging the intentional nature of the modification.
Data Source
AI summary
A risk evaluation device acquires target data including an explanatory variable value list and a target variable value, calculates a confidence score for each partial model of a target model, wherein the target model includes the partial model for each of a plurality of ways of performing the first class classification, and wherein the partial model indicates, for each class in a class classification performed using a combination of the first class classification and the second class classification, a degree to which an element of a second set generated for each partial model from a predetermined first set is classified into the class, and evaluates a possibility that the target data is included in the first set based on the confidence score of each partial model.


