Risk Evaluation Device for Membership Inference Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing models comprising multiple partial models face challenges in effectively evaluating the risk of information leakage, particularly in membership inference attacks where training data is estimated from inference results.

Innovation Solution

A risk evaluation device and method that acquire target data, calculate confidence scores for each partial model, and evaluate the possibility of target data being included in a training set, with adjustments for confidence scores indicating zero elements in a class to indicate one or more elements, thereby assessing and mitigating information leakage risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If confidence scores are calculated for each partial model to evaluate information leakage risk, then measurement precision of risk evaluation is improved, but device complexity increases due to multiple partial models and confidence score calculations

Engineering Contradiction:
Improverisk evaluation precisionVSAvoidmodel structure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the evaluation process into multiple partial models, each handling specific aspects of risk assessment. By segmenting the overall evaluation into manageable partial models with individual confidence scores, the system achieves comprehensive risk measurement while maintaining structured complexity that can be systematically managed and interpreted.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal evaluation framework where multiple partial models serve the common function of risk assessment. Each partial model contributes to the overall confidence score calculation, allowing the system to evaluate information leakage risk across different scenarios and data types using a unified multi-model approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If confidence scores indicating zero elements are rewritten to indicate one or more elements, then loss of information is reduced by preventing complete exclusion of classes, but measurement precision is reduced due to intentional modification of calculated values

Engineering Contradiction:
Improveinformation completenessVSAvoidconfidence score accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent applies preliminary anti-action by pre-modifying confidence scores that would otherwise indicate zero elements. This preventive measure ensures that no class is completely excluded from consideration, maintaining information completeness while being applied systematically before final risk evaluation decisions are made.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent changes the parameter values of confidence scores from their calculated state to a modified state where zero values are transformed to indicate one or more elements. This parameter change balances the need to preserve information about all possible classes while acknowledging the intentional nature of the modification.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240403657A1Risk evaluation device, data protection device, and risk evaluation method
Publication Date: 2024.12.05 NEC CORP
  • US20240403657A1 patent drawing
  • US20240403657A1 patent drawing
  • US20240403657A1 patent drawing

AI summary

A risk evaluation device acquires target data including an explanatory variable value list and a target variable value, calculates a confidence score for each partial model of a target model, wherein the target model includes the partial model for each of a plurality of ways of performing the first class classification, and wherein the partial model indicates, for each class in a class classification performed using a combination of the first class classification and the second class classification, a degree to which an element of a second set generated for each partial model from a predetermined first set is classified into the class, and evaluates a possibility that the target data is included in the first set based on the confidence score of each partial model.