Empirical Evaluation of Record Reconstruction Risk from Model Explanations with Differential Privacy
摘要
Explainability has gained attention to ensure fairness and transparency in machine learning models, providing users with an understanding of artificial intelligence (AI) models. Machine Learning as a Service (MLaaS) platforms offer several methods to explain model outputs. Patel et al. proposed DPGD-Explain, model explanations with differential privacy. They proved that the DPGD-Explain provides secure model explanations in the sense of central differential privacy. Nevertheless, it remains unclear if model explanations with a differential privacy guarantee are vulnerable against the record reconstruction attack given some pairs of input data and model explanations. In this study, we investigate the record reconstruction risk of DPGD-Explain, in terms of privacy budget and quality.