Pith. sign in

REVIEW

InstaHide's Sample Complexity When Mixing Two Private Images

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2011.11877 v2 pith:QVJ7M463 submitted 2020-11-24 cs.LG cs.CCcs.CRcs.DSstat.ML

classification cs.LGcs.CCcs.CRcs.DSstat.ML
keywords instahideimagesprivatetrainingattacksdatabecomecomplexity
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Training neural networks usually require large numbers of sensitive training data, and how to protect the privacy of training data has thus become a critical topic in deep learning research. InstaHide is a state-of-the-art scheme to protect training data privacy with only minor effects on test accuracy, and its security has become a salient question. In this paper, we systematically study recent attacks on InstaHide and present a unified framework to understand and analyze these attacks. We find that existing attacks either do not have a provable guarantee or can only recover a single private image. On the current InstaHide challenge setup, where each InstaHide image is a mixture of two private images, we present a new algorithm to recover all the private images with a provable guarantee and optimal sample complexity. In addition, we also provide a computational hardness result on retrieving all InstaHide images. Our results demonstrate that InstaHide is not information-theoretically secure but computationally secure in the worst case, even when mixing two private images.

Discussion (0). Sign in to comment.

Pith tools