kth.sePublications KTH
Operational message
There are currently operational disruptions. Troubleshooting is in progress.
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Privacy-Enhancing Sub-Sampling Meets Model Inversion Attacks
KTH, School of Electrical Engineering and Computer Science (EECS).
KTH, School of Electrical Engineering and Computer Science (EECS).
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This work examines how optimizer selection and sub-sampling strategies affect model performance and adversarial vulnerability under differential privacy. We evaluate Differentially Private Stochastic Gradient Descent (DP-SGD) with and without sub-sampling, measuring attack success through classification rates, pixel similarity (PSNR), and structural similarity (SSIM). Results show that switching from Adam to DP-SGD, combined with sub-sampling, lowers adversarial classification accuracy across privacy budgets but can also increase pixel-level similarity in reconstructed inputs. These findings highlight a tension between differential privacy and perceptual privacy under standard DP training. Specifically, we simulate a black-box model inversion attack, where the adversary can only query the model’s outputs without access to internal parameters. This threat model reflects realistic deployment scenarios and underscores the importance of defenses that do not rely on obfuscation but provide formal privacy guarantees.This work examines how optimizer selection and sub-sampling strategies affect model performance and adversarial vulnerability under differential privacy. We evaluate Differentially Private Stochastic Gradient Descent (DP-SGD) with and without sub-sampling, measuring attack success through classification rates, pixel similarity (PSNR), and structural similarity (SSIM). Results show that switching from Adam to DP-SGD, combined with sub-sampling, lowers adversarial classification accuracy across privacy budgets but can also increase pixel-level similarity in reconstructed inputs. These findings highlight a tension between differential privacy and perceptual privacy under standard DP training. Specifically, we simulate a black-box model inversion attack, where the adversary can only query the model’s outputs without access to internal parameters. This threat model reflects realistic deployment scenarios and underscores the importance of defenses that do not rely on obfuscation but provide formal privacy guarantees.

Abstract [sv]

Detta arbete undersöker hur valet av optimeringsalgoritm och användningen av delmängdsurval påverkar modellens prestanda och sårbarhet för attacker under differentiell sekretess. Vi utvärderar stokastisk gradientnedstigning med differentiell sekretess (DP-SGD) med och utan delmängdsurval genom att mäta attackframgång baserat på klassificeringsgrad, pixelsimilaritet (PSNR) och strukturell similaritet (SSIM). Resultaten visar att övergången från Adam till DP-SGD, i kombination med delmängdsurval, sänker den adversariella klassificeringsnoggrannheten över olika integritetsbudgetar, men samtidigt kan öka pixelnivåns likhet i rekonstruerade indata. Dessa resultat belyser en konflikt mellan medlemskapssekretess och perceptuell sekretess vid standardiserad med differentiell sekretess. Specifikt simulerar vi en black-box model inversionsattack, där angriparen enbart kan göra förfrågningar till modellens utdata utan tillgång till interna parametrar. Denna hotmodell speglar realistiska driftsmiljöer och understryker vikten av försvar som inte förlitar sig på fördoldhet utan erbjuder formella sekretessgarantier.

Place, publisher, year, edition, pages
2025. , p. 541-548
Series
TRITA-EECS-EX ; 2025:154
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Identifiers
URN: urn:nbn:se:kth:diva-376175OAI: oai:DiVA.org:kth-376175DiVA, id: diva2:2034549
Supervisors
Examiners
Projects
Kandidatexamensarbete i Elektroteknik 2025, EECS, KTHAvailable from: 2026-02-02 Created: 2026-02-02

Open Access in DiVA

fulltext(80627 kB)31 downloads
File information
File name FULLTEXT01.pdfFile size 80627 kBChecksum SHA-512
35ce0a386dafe4649eb99cbe0efdfed651a3c9044e3339612422234d17a7e8ec21d4fd4aa201500c3c7a8f57194994b78b3e0cfbd5319ecd49f18a5d8a7ff775
Type fulltextMimetype application/pdf

By organisation
School of Electrical Engineering and Computer Science (EECS)
Electrical Engineering, Electronic Engineering, Information Engineering

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 4100 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf