Uppsats

Forgotten-by-Design for Privacy-Preserving AI : An Empirical Study of Membership Inference Mitigation

Yrkesexamen på avancerad nivå

Luleå tekniska universitet/Institutionen för system- och rymdteknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

The prominence of artificial intelligence has increased at an unprecedented pace in recent years, as large corporations deploy commercially available models that can be queried at a moment’s notice. In parallel, regulatory bodies such as the European Union have introduced regulations including the GDPR that formalize the “Right to be Forgotten”, to preserve user privacy. However, due to the inherent memorization properties of machine learning models, the concrete removal of individual data points cannot be guaranteed. Direct erasure may incur severe impact on an AI model’s utility, potentially rendering the model ineffective. This limitation is a considerable issue, particularly in an adversarial setting, where membership inference attacks have been shown to expose training data. To mitigate such data leakage, privacy-preserving methods have been developed. Central to this thesis is the proactive Forgotten-by-Design data obfuscation technique. During training under the Forgotten-by-Design strategy, instance-specific noise is injected and vulnerable data points are assigned lower weights, thereby reducing contribution to the learned model and limiting memorization. The novel approach demonstrates promising initial results; however, the technique requires further empirical testing to prove robustness across datasets and model architectures. This is the primary objective of this thesis, while simultaneously examining the optimal privacy-utility trade-off that the technique can obtain. Experimental results indicate that Forgotten-by-Design consistently provides robust vulnerability mitigation across several datasets and model architectures when evaluated against two state-of-the-art membership inference attacks, namely the Likelihood Ratio Attack and the Robust Membership Inference Attack. Furthermore, the results show distinct privacy-utility trade-off regimes that achieve strong mitigation while maintaining near-baseline model utility.

Information

Lärosäte / institution
Luleå tekniska universitet/Institutionen för system- och rymdteknik
Publiceringsdatum
2026
Uppsatstyp
Yrkesexamen på avancerad nivå
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.