An empirical privacy risk assessment method for machine learning models towards GDPR’s “Data protection by design and by default” requirement
Abstract The General Data Protection Regulation (GDPR) requires adherence to a paradigm called “Data Protection by Design and by Default” within data processing systems, though machine learning models tend to expose latent privacy risks that are currently inadequately quantified. The aim of this work is to present a comprehensive empirical method to assess privacy risks within machine learning models quantitatively against GDPR requirements. The work presents a paradigm combining three main aspects: model inversion attacks, membership inference attacks, and attribute inference attacks on a single quantitative methodological level. The methodological approach is implemented via systematic experiments on multiple architectures such as deep neural networks, decision trees, and support vector machines to assertively prove its capability to detect privacy risks with an average detection accuracy rate of 89.3%. The methodological approach uses mathematical constructs to represent quantifiable risk scores within a range of 0 to 100, assisting in taking informed technical decisions on model usage. The methodological approach is experimentally implemented on five standard benchmarking datasets to assertively prove that deep neural networks tend to express higher values of privacy risk scores (µ = 74.1) and tend to have relatively low expression within ensemble methodological approaches (µ = 51.6 values). The methodological approach gives opportunities to take informed technical decisions on implementing technical-organizational measures within GDPR’s paradigm guidelines on “Data Protection by Design and by Default.”
Authors
- Bing Han
Institutions
- The University of Sydney (AU)
- Cooperative Trials Group for Neuro-Oncology (AU)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-09-21
- DOI
- https://doi.org/10.1038/s41598-026-71546-7
- Primary Topic
- Ethics and Social Impacts of AI
- Type
- article
- Field-Weighted Citation Impact
- 0.00