[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-121615-en":3,"doc-seo-121615-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},121615,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","Dataset correlation inference attacks against machine learning models - Abstract","Machine learning models are widely deployed for automated decisions, yet training on sensitive datasets can cause leakage of both individual information and global dataset properties. This work advances property inference by introducing a dataset correlation inference attack that infers correlations between input variables. It leverages spherical parametrization constraints on correlation matrices and adds a shadow-modelling, Gaussian-copula-based meta-model attack, evaluated on Logistic Regression and MLP.","Dataset correlation inference attacks against machine learning models  \nAna-Maria Cret¸u* Imperial College London [a.cretu@imperial.ac.uk](a.cretu@imperial.ac.uk)  \nFlorent Gupin*  \nImperial College London ﬂ[orent.guepin@imperial.ac.uk](orent.guepin@imperial.ac.uk)  \nYves-Alexandre de Montjoye Imperial College London [demontjoye@imperial.ac.uk](demontjoye@imperial.ac.uk)  \narXiv :2112 .08806v1 [ cs .LG] 16 Dec 2021  \nAbstract—Machine learning models are increasingly used by businesses and organizations around the world to automate tasks and decision making. Trained on potentially sensitive datasets, machine learning models have been shown to leak information about individuals in the dataset as well as global dataset information. We here take research in dataset property inference attacks one step further by proposing a new attack against ML models: a dataset correlation inference attack, where an attacker's goal is to infer the correlation between input variables of a model. We ﬁrst show that an attacker can exploit the spherical parametrization of correlation matrices, imposing boundaries on the correlation coefﬁcients, to make an informed guess. This means that using only the correlation between the input variables and the target variable, an attacker can infer the correlation between two input variables much better thana random guess baseline. We propose a second attack which exploits the access to a machine learning model using shadow modelling to reﬁne the guess. Our attack uses Gaussian copulabased generative modelling to generate synthetic datasets with a wide variety of correlations in order to train a meta model for the correlation inference task. We evaluate our attack against Logistic Regression and Multi-layer perceptron models and show it to outperform the model-less attack. We ﬁnd the MLP to be less vulnerable to our attacks. Our results show that the accuracy of the second, machine learning-based attack decreases with the number of variables and converges towards the accuracy of the model-less attack. However, correlations between input variables which are highly correlated with the target variable are more vulnerable regardless of the number of variables. Our work bridges the gap between what can be considered a global leakage about the training dataset and invididual-level leakages. When coupled with marginal leakage attacks, it might also constitute a ﬁrst step towards dataset reconstruction.  \nIndex Terms—property inference attacks, machine learning privacy  \nI. INTRODUCTION  \nMachine learning models are increasingly used by businesses, researchers and organizations to automate processes and decision making. The applications of machine learning are very broad, ranging from research [1], personalized recommendations [2], anomaly detection, spam detection, content moderation [3], [4], automated completion of emails [5], speech or object recognition [6], [7], insurance risk assessment [8], screening of job applicants [9], predicting healthcare outcomes [10] to medical diagnosis [11] . The growth of machine learning has been driven by decreasing storage costs for data and by people's increasing use of smartphones and  \n*These authors contributed equally and are listed alphabetically.  \nthe Internet of things generating a lot of data [12], [13] . In response to the growing impact of machine learning on society, policymakers around the world are now discussing bills to regulate its use [14] .  \nWhile the performance of machine learning models beneﬁts from large amounts of training data, these data can be very sensitive. Typical datasets used in real-world applications consist of user emails, patient records, voice recordings, images,ﬁne-grained behavioural logs or interaction data. As models are being shared widely through APIs, either commercially or by researchers for reproducibility reasons, their release raises concerns about the potential leakage of sensitive information about the training data. The main rele","cbCaieFNgxQG5t4s","https://ap.wps.com/l/cbCaieFNgxQG5t4s","pdf",1350744,1,15,"English","en",105,"# Abstract\n## Introduction\n## Problem setting: sensitive datasets and model release\n## Prior work: membership, attribute, link stealing, and reconstruction attacks\n## Property inference and correlation leakage motivation","[{\"question\":\"What is the proposed dataset correlation inference attack aiming to infer?\",\"answer\":\"It aims to infer the correlation between input variables of a machine learning model.\"},{\"question\":\"How does the first attack exploit correlation structure?\",\"answer\":\"It uses spherical parametrization constraints of correlation matrices to restrict correlation coefficients, enabling better-than-random inference from correlations involving the target variable.\"},{\"question\":\"How is the second, model-based attack constructed and evaluated?\",\"answer\":\"It uses shadow modelling with Gaussian copula-based generative synthetic datasets to train a meta model for correlation inference, then is evaluated against Logistic Regression and multi-layer perceptron models.\"}]","Dataset correlation inference attacks against machine learning models - Abstract | PDF",1785805668,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"dataset-correlation-inference-attacks-against-machine-learning-models-abstract","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/dataset-correlation-inference-attacks-against-machine-learning-models-abstract/121615/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the proposed dataset correlation inference attack aiming to infer?","Question",{"text":75,"@type":76},"It aims to infer the correlation between input variables of a machine learning model.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the first attack exploit correlation structure?",{"text":80,"@type":76},"It uses spherical parametrization constraints of correlation matrices to restrict correlation coefficients, enabling better-than-random inference from correlations involving the target variable.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the second, model-based attack constructed and evaluated?",{"text":84,"@type":76},"It uses shadow modelling with Gaussian copula-based generative synthetic datasets to train a meta model for correlation inference, then is evaluated against Logistic Regression and multi-layer perceptron models.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]