On Limiting the Predictive Exposure of Learned Models
Abstract
The outputs of machine learning algorithms can reveal properties of the underlying populations in the dataset. Some of these aggregate properties of the dataset may be considered sensitive or proprietary (such as the overall customer base and marketing strategy of a business, rather than a particular transaction). Thus, we want to limit the information leaked from a learning algorithm about a sensitive aggregate property of the unknown portion of the dataset. We formalize this leakage as predictive exposure. Given a portion of a dataset generated by a stochastic process, predictive exposure measures how well an observer can predict statistics about sensitive properties of the population of unknown individuals, before and after observing the algorithm's output. We show that when the leaked portion of the dataset is generated by a stationary, ergodic, mixing process, we can study the asymptotic predictive exposure of an algorithm using a classic tool, the generalized method of moments hansen1982. Our analysis shows how learning algorithms can be modified to limit predictive exposure. Using our analysis, we derive an exposure-limiting output perturbation scheme for ERM.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.