OR with a White Hat: Evidencing Privacy Vulnerabilities in ML Models

Thibaut Vidal

Présentation (2026)

Accéder à ce document
Disponible
Libre accès au texte intégral dans PolyPublie
Autre contenu
Vidéo Vidéo • 914MB •

Résumé

The deployment of machine learning models in high-stakes domains raises profound questions about the privacy of the data used to train them. In this talk, I will show how combinatorial and inverse optimization can provide a rigorous methodological backbone for analyzing, quantifying, and ultimately mitigating privacy risks in modern ML pipelines. I will first discuss a white-box reconstruction attack that formulates the recovery of a random forest training data as a maximum-likelihood problem solved with constraint programming. Remarkably, this approach can often reconstruct entire datasets, even from forests with only a few trees. Next, we turn to black-box access and explainability-driven interfaces. Counterfactual explanations (now increasingly needed and exposed through ML APIs) represent a powerful attack surface. Using tools from online optimization and competitive analysis, we derive tight bounds on the number of counterfactual queries required to exactly extract tree-based models and introduce new algorithms achieving provably perfect fidelity. Finally, I will examine the protection offered by differential privacy. Focusing on ε-DP random forests, we demonstrate that even models satisfying strict DP guarantees can still leak meaningful, dataset-specific information in practice, unless the privacy noise is increased to the point where the model loses most of its predictive value.

Renseignements supplémentaires:
SCALE-AI Chair in Data-Driven Supply Chains
Adresse URL de PolyPublie:
Nom de la conférence:
BIRS Workshop
Lieu de la conférence:
Banff, AB, Canada
Date(s) de la conférence:
2026-05-22 - 2026-05-27
Maison d'édition:
Banff International Research Station for Mathematical Innovation and Discovery
OAI:
oai:publications.polymtl.ca:75842
ORCID
Date du dépôt:
01 avr. 2026 09:51
Dernière modification:
08 oct. 2026 19:06
Citer en APA 7:
Vidal, T. (mai 2026). OR with a White Hat: Evidencing Privacy Vulnerabilities in ML Models [Présentation]. Dans BIRS Workshop, Banff, AB, Canada. https://doi.org/10.14288/1.0451591

Statistiques

Total des téléchargements à partir de PolyPublie

Téléchargements par année

Provenance des téléchargements

Dimensions

Actions réservées au personnel

Afficher document
Afficher document