Differentially Private Counterfactuals via Functional Mechanism

08/04/2022
by   Fan Yang, et al.
6

Counterfactual, serving as one emerging type of model explanation, has attracted tons of attentions recently from both industry and academia. Different from the conventional feature-based explanations (e.g., attributions), counterfactuals are a series of hypothetical samples which can flip model decisions with minimal perturbations on queries. Given valid counterfactuals, humans are capable of reasoning under “what-if” circumstances, so as to better understand the model decision boundaries. However, releasing counterfactuals could be detrimental, since it may unintentionally leak sensitive information to adversaries, which brings about higher risks on both model security and data privacy. To bridge the gap, in this paper, we propose a novel framework to generate differentially private counterfactual (DPC) without touching the deployed model or explanation set, where noises are injected for protection while maintaining the explanation roles of counterfactual. In particular, we train an autoencoder with the functional mechanism to construct noisy class prototypes, and then derive the DPC from the latent prototypes based on the post-processing immunity of differential privacy. Further evaluations demonstrate the effectiveness of the proposed framework, showing that DPC can successfully relieve the risks on both extraction and inference attacks.

READ FULL TEXT

page 6

page 9

research
06/16/2020

Model Explanations with Differential Privacy

Black-box machine learning models are used in critical decision-making d...
research
09/13/2022

Differentially Private Genomic Data Release For GWAS Reproducibility

With the rapid development of technology in genome-related fields, resea...
research
04/05/2023

PrivGraph: Differentially Private Graph Data Publication by Exploiting Community Information

Graph data is used in a wide range of applications, while analyzing grap...
research
12/08/2022

XRand: Differentially Private Defense against Explanation-Guided Attacks

Recent development in the field of explainable artificial intelligence (...
research
01/26/2020

Bilevel Optimization for Differentially Private Optimization

This paper studies how to apply differential privacy to constrained opti...
research
06/16/2021

Model-Based Counterfactual Synthesizer for Interpretation

Counterfactuals, serving as one of the emerging type of model interpreta...
research
03/25/2021

Realistic Differentially-Private Transmission Power Flow Data Release

For the modeling, design and planning of future energy transmission netw...

Please sign up or login with your details

Forgot password? Click here to reset