A Comprehensive Study of Privacy Risks in Curriculum Learning
Joann Qiongna Chen, Xinlei He, Zheng Li, Yang Zhang, Zhou Li
OpenReview ground truth
TL;DR — We study the privacy risks introduced by curriculum learning through the lens of membership inference attack (MIA) and attribute inference attack (AIA)
Abstract
Curriculum learning (CL) is a machine learning technique that progressively trains a model on data of increasing difficulty or complexity. This way, the model can learn more efficiently and achieve better performance than random or uniform sampling of data. However, most existing works focus on improving the performance of CL and its privacy risks have never been studied. In this work, we take the first step to investigate the privacy leakage of CL through the lens of membership inference attack (MIA) and attribute inference attack (AIA). Our evaluation of 9 benchmark datasets using various attack methods (NN-based, metric-based, label-only MIA, and NN-based AIA) highlights new insights. First, MIA is slightly more effective with CL, especially on a subset of challenging training samples. Second, models trained with CL are less susceptible to AIA compared to MIA. Third, established defense techniques like DP-SGD, MemGuard, and MixupMMD remain effective under CL, albeit with a notable accuracy impact for DP-SGD. Lastly, we propose a novel MIA called Diff-Cali, which leverages difficulty scores to enhance calibration and effectiveness against all CL and normal training methods. With this study, we hope to draw the community's attention to the unintended privacy risks of emerging machine-learning techniques and develop new attack benchmarks and defense solutions.
Author context
Most prolific author: 6 submissions (credibility 1.00).
No mass-submission penalty for this paper (authors within normal submission volume).
Aggregate statistics only — no individual author rankings.
Ranking trajectory
Percentile by tournament round — convergence indicates rating stability.
Battle history — 34 comparisons
Ranked above opponent in 44% of matchups.
- ▲ beat Gaussian Process-Based Corruption-resilien… ×6
- ▼ lost to Model Inversion Robustness: Can Transfer L… ×4
- ▲ beat A Novel Autoencoder Based Approach for Cou… ×4
- ▼ lost to Amplifying Training Data Exposure through … ×4
- ▲ beat Towards the Vulnerability of Watermarking … ×4
Judge assessments
Mean overall score 0.0 ± 0.0 (n = 34)