[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122937-en":3,"doc-seo-122937-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122937,4398048950312,"Violet","https://ap-avatar.wpscdn.com/avatar/400002538284de19e3c?_k=1778320343897328908",8,"Research & Report","Differentially Private and Adversarially Robust Machine Learning - An Empirical Evaluation","Malicious adversaries can compromise machine learning systems by extracting sensitive information or by evading models through crafted perturbations. Prior defenses typically study privacy and security in isolation, even though real systems may face simultaneous attacks. This work investigates combining adversarial training with differential privacy to withstand concurrent threats. It benchmarks the DP-Adv approach via membership inference and shows its privacy matches that of non-robust private models, emphasizing the need to study privacy guarantees in dynamic training settings.","Differentially Private and Adversarially Robust Machine Learning:  \nAn Empirical Evaluation  \nJanvi Thakkar 1 , Giulio Zizzo2 , Sergio Maffeis 1  \n1Department of Computing, Imperial College London  \n2 IBM Research Europe  \n[janvi.thakkar22@imperial.ac.uk](janvi.thakkar22@imperial.ac.uk), [giulio.zizzo2@ibm.com](giulio.zizzo2@ibm.com), [sergio.maffeis@imperial.ac.uk](sergio.maffeis@imperial.ac.uk)  \narXiv :2401 . 10405v1 [ cs .LG] 18 Jan 2024  \nAbstract  \nMalicious adversaries can attack machine learning models to infer sensitive information or damage the system by launching a series of evasion attacks. Although various work addresses privacy and security concerns, they focus on individual defenses, but in practice, models may undergo simultaneous attacks. This study explores the combination of adversarial training and differentially private training to defend against simultaneous attacks. While differentially-private adversarial training, as presented in DP-Adv (Bu, Li, and Zhao 2021), outperforms the other state-of-the-art methods in performance, it lacks formal privacy guarantees and empirical validation. Thus, in this work, we benchmark the performance of this technique using a membership inference attack and empirically show that the resulting approach is as private as non-robust private models. This work also highlights the need to explore privacy guarantees in dynamic training paradigms.  \nIntroduction  \nDespite their success, machine learning (ML) models are susceptible to various malicious attacks. Privacy attacks like model extraction (Tramr et al. 2016) and membership inference attacks (Shokri et al. 2017) try to infer sensitive information of the model and its training datasets. Evasion attacks using adversarial samples (Szegedy et al. 2013) fool the model into predicting wrong outcomes, critically increasing the risks associated with ML models.  \nMultiple studies have focused on devising techniques topreserve the privacy and security of ML models independently from each other. Several strategies were proposed (Chaudhuri, Monteleoni, and Sarwate 2011; Kifer, Smith, and Thakurta 2012; Rubinstein et al. 2009) to defend against privacy attacks. One of the widely used approaches is to employ differential privacy in the training algorithm, DPSGD (Abadi et al. 2016), to safeguard the privacy of individual datapoints.  \nIn response to evasion attacks, defense techniques such as adversarial training augment the training set with adversarial samples, generated using FGSM (Goodfellow, Shlens, and Szegedy 2014) or PGD (Madry et al. 2017), significantly increasing the robustness of the resulting model.  \nPPAI-24: The 5th AAAI Workshop on Privacy-Preserving Artificial Intelligence  \nThere is little work addressing these concerns at the sametime. Preliminary research observed that applying DP makes the model more vulnerable to adversarial attacks (Tursynbek, Petiushko, and Oseledets 2020), and similarly, using adversarial training techniques makes the model more susceptible to privacy attacks (Shokri et al. 2017) .  \nRecent work (Phan et al. 2020) proposed the StoBatch algorithm, which combines differential privacy and adversarial training to defend against simultaneous privacy and security attacks. The primary goal was to convert the training data to DP-private data and then leverage these DPtraining samples to generate adversarial samples. However, this comes at the cost of model utility and robustness.  \nDP-Adv (Bu, Li, and Zhao 2021) tried addressing the limitations of StoBatch, by adopting the traditional DPSGD strategy (Abadi et al. 2016) and replacing each training sample with exactly one adversarial example. This approach is more practical, and provides improved utility and robustness compared to StoBatch. However, the approach has not been empirically evaluated. Furthermore there is a concern that owing to the use of adversarial samples, which are generated using a non-private optimizer, it may not be as private as DPSGD","cbCaieVsfcExcDi9","https://ap.wps.com/l/cbCaieVsfcExcDi9","pdf",507288,1,9,"English","en",105,"# Abstract\n# Introduction\n## Privacy attacks\n## Evasion attacks\n## Prior work and motivation\n# Approach: DP-Adv\n## Core intuition\n## Optimization formulation\n## Key algorithm steps","[{\"question\":\"How is the privacy of the DP-Adv approach evaluated?\",\"answer\":\"The work benchmarks DP-Adv using a membership inference attack to empirically assess whether the resulting model preserves privacy comparable to non-robust private models.\"}]","Differentially Private and Adversarially Robust Machine Learning - An Empirical Evaluation | PDF",1785813773,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"differentially-private-and-adversarially-robust-machine-learning-an-empirical-evaluation","",{"@graph":36,"@context":77},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/differentially-private-and-adversarially-robust-machine-learning-an-empirical-evaluation/122937/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"How is the privacy of the DP-Adv approach evaluated?","Question",{"text":75,"@type":76},"The work benchmarks DP-Adv using a membership inference attack to empirically assess whether the resulting model preserves privacy comparable to non-robust private models.","Answer","https://schema.org",{"og:url":52,"og:type":79,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":81,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,115,119,122,126],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Religion & Spirituality",20,"religion-spirituality",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":117,"slug":121},"World Cup","world-cup",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":123,"slug":125},10,"Lifestyle","lifestyle",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":98,"slug":129},19,"General","general"]