arXiv Machine Learning

Position: Privacy Is a Claim, Not a Property of Synthetic Data

arXiv Machine Learning
1d ago

Rethinking Anonymity Claims in Synthetic Data Generation: A Model-Centric Privacy Attack Perspective

The paper argues that evaluating anonymity in synthetic data generation must focus on the generative model rather than just the resulting dataset. It interprets GDPR definitions of personal data and anonymization under realistic model-access scenarios, mapping these to state‑of‑the‑art privacy attacks. The authors conclude that synthetic data alone is insufficient for anonymization, and that Differential Privacy offers stronger protection than Similarity‑based Privacy Metrics.

By Georgi Ganev, Emiliano De Cristofaro
arXiv Machine Learning
Sep 18

On the Inherent Privacy Amplification of Missing Data

The paper explores how missing data can inherently enhance privacy in machine learning. By integrating missingness into a differential privacy framework, the authors demonstrate that the absence of certain features can amplify privacy guarantees without altering the underlying algorithm. This reveals a previously overlooked interaction between data incompleteness and formal privacy protections.

By Simon Roburin (LPSM), Rafa{\"e}l Pinot (LPSM), Erwan Scornet (LPSM)
arXiv Machine Learning
Sep 11

SoK: Privacy Attacks on Machine Learning via Explainable AI

The paper surveys 25 studies that use explainable AI to compromise machine learning models, covering attacks such as model extraction, membership inference, and model inversion. It distinguishes between how explanations are obtained—through target releases, attacker-derived methods, secondary disclosure, privileged access, or global artifacts—and shows that explanations can lower extraction costs and reveal membership signals via statistics, recourse distance, and robustness. The authors compare threat models, signals, and defenses, concluding that no single explanation type is always unsafe and that protection must be tailored to the specific acquisition path and target asset.

By Abdullah Caglar Oksuz, Anisa Halimi, Erman Ayday