Page 749

Ming Ding | Information Security and

Privacy Group | Data61, CSIROPrivacy risk assessment –Examples

•Membership inference: Prℎ∈𝑥|𝑦

➢Intuition: The probability of determining whether an individual ℎis in 𝑥

➢This metric is widely used in a machine learning setting, where 𝑥could be a training dataset and 𝑦

could be an observed machine learning model or some observed machine learning outputs

➢This metric is usually evaluated using empirical experiments only

➢The smaller the metric, the stronger the privacy protection

Original data x

(sensitive info: s

non-sensitive info: u)Output/Observation y

(data, query answer, AI/ML

models/parameters, etc.)