Uppsats
Forgotten-by-Design for Privacy-Preserving AI : An Empirical Study of Membership Inference Mitigation
Yrkesexamen på avancerad nivå
Luleå tekniska universitet/Institutionen för system- och rymdteknik
Publicerad: 2026
Språk: Engelska
Sammanfattning
The prominence of artificial intelligence has increased at an unprecedented pace in recent years, as large corporations deploy commercially available models that can be queried at a moment’s notice. In parallel, regulatory bodies such as the European Union have introduced regulations including the GDPR that formalize the “Right to be Forgotten”, to preserve user privacy. However, due to the inherent memorization properties of machine learning models, the concrete removal of individual data points cannot be guaranteed. Direct erasure may incur severe impact on an AI model’s utility, potentially rendering the model ineffective. This limitation is a considerable issue, particularly in an adversarial setting, where membership inference attacks have been shown to expose training data. To mitigate such data leakage, privacy-preserving methods have been developed. Central to this thesis is the proactive Forgotten-by-Design data obfuscation technique. During training under the Forgotten-by-Design strategy, instance-specific noise is injected and vulnerable data points are assigned lower weights, thereby reducing contribution to the learned model and limiting memorization. The novel approach demonstrates promising initial results; however, the technique requires further empirical testing to prove robustness across datasets and model architectures. This is the primary objective of this thesis, while simultaneously examining the optimal privacy-utility trade-off that the technique can obtain. Experimental results indicate that Forgotten-by-Design consistently provides robust vulnerability mitigation across several datasets and model architectures when evaluated against two state-of-the-art membership inference attacks, namely the Likelihood Ratio Attack and the Robust Membership Inference Attack. Furthermore, the results show distinct privacy-utility trade-off regimes that achieve strong mitigation while maintaining near-baseline model utility.
Information
- Författare
- Vadman Lidberg, Joakim
- Lärosäte / institution
- Luleå tekniska universitet/Institutionen för system- och rymdteknik
- Publiceringsdatum
- 2026
- Uppsatstyp
- Yrkesexamen på avancerad nivå
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
M1-uppsats, Jönköping University/JTH, Avdelningen för datateknik och informatik
Seyhani Porshekoh, Artin
Publicerad: 2026
Master-uppsats, Luleå tekniska universitet/Institutionen för system- och rymdteknik
Ali, Qasim
Publicerad: 2026
Yrkesexamen på avancerad nivå, Uppsala universitet/Avdelningen för systemteknik
Vigholm, Albin
Publicerad: 2026
Yrkesexamen på avancerad nivå, Luleå tekniska universitet/Institutionen för ekonomi, teknik, konst och samhälle
Holmström, Ellen
Publicerad: 2026
Yrkesexamen på avancerad nivå, Luleå tekniska universitet/Institutionen för ekonomi, teknik, konst och samhälle
Åström, Tuva, Nilsson, Matilda
Publicerad: 2026
Yrkesexamen på avancerad nivå, Luleå tekniska universitet/Institutionen för ekonomi, teknik, konst och samhälle
Nordlander, Jonas
Publicerad: 2026