Papers
Topics
Authors
Recent
Search
2000 character limit reached

TMI! Finetuned Models Leak Private Information from their Pretraining Data

Published 1 Jun 2023 in cs.LG and cs.CR | (2306.01181v3)

Abstract: Transfer learning has become an increasingly popular technique in machine learning as a way to leverage a pretrained model trained for one task to assist with building a finetuned model for a related task. This paradigm has been especially popular for privacy\textit{privacy} in machine learning, where the pretrained model is considered public, and only the data for finetuning is considered sensitive. However, there are reasons to believe that the data used for pretraining is still sensitive, making it essential to understand how much information the finetuned model leaks about the pretraining data. In this work we propose a new membership-inference threat model where the adversary only has access to the finetuned model and would like to infer the membership of the pretraining data. To realize this threat model, we implement a novel metaclassifier-based attack, TMI\textbf{TMI}, that leverages the influence of memorized pretraining samples on predictions in the downstream task. We evaluate TMI\textbf{TMI} on both vision and natural language tasks across multiple transfer learning settings, including finetuning with differential privacy. Through our evaluation, we find that TMI\textbf{TMI} can successfully infer membership of pretraining examples using query access to the finetuned model. An open-source implementation of TMI\textbf{TMI} can be found on GitHub: https://github.com/johnmath/tmi-pets24.

Citations (11)

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.

Tweets

Sign up for free to view the 2 tweets with 15 likes about this paper.