Effectiveness of L2 Regularization in Privacy-Preserving Machine Learning

preprint OA: closed
Full text JSON View at publisher
AI-generated deep summary by claude@2026-07, 2026-07-03 · read from full text

This paper studies how L2 regularization and differential privacy affect privacy risks from membership inference attacks against machine learning models trained on sensitive data, focusing on whether adversaries can infer if a specific data point was included in training. The authors conceptually frame L2 regularization as a common anti-overfitting technique that could change membership inference effectiveness and compare it against differential privacy as an established privacy-preserving approach. A stated limitation is that the work is presented as a preprint and the article notes preliminary, unreviewed status (with additional details relegated to supplementary material). Relevance to endometriosis: it does not explicitly discuss endometriosis or adenomyosis; it was included in the corpus via a keyword match in the upstream search index.

Read from the paper's body, not the abstract. Not a substitute for reading the paper. No clinical advice. How this works

Abstract

Artificial intelligence, machine learning, and deep learning as a service have become the status quo for many industries, leading to the widespread deployment of models that handle sensitive data. Well-performing models, the industry seeks, usually rely on a large volume of training data. However, the use of such data raises serious privacy concerns due to the potential risks of leaks of highly sensitive information. One prominent threat is the Membership Inference Attack, where adversaries attempt to deduce whether a specific data point was used in a model's training process. An adversary's ability to determine an individual's presence represents a significant privacy threat, especially when related to a group of users sharing sensitive information. Hence, well-designed privacy-preserving machine learning solutions are critically needed in the industry. In this work, we compare the effectiveness of L2 regularization and differential privacy in mitigating Membership Inference Attack risks. Even though regularization techniques like L2 regularization are commonly employed to reduce overfitting, a condition that enhances the effectiveness of Membership Inference Attacks, their impact on mitigating these attacks has not been systematically explored.
Full text 7,280 characters · extracted from preprint-html · click to expand
Effectiveness of L2 Regularization in Privacy-Preserving Machine Learning | Authorea try { document.documentElement.classList.add('js'); } catch (e) { } var _gaq = _gaq || []; _gaq.push(['_setAccount', 'G-8VDV14Y67G']); _gaq.push(['_trackPageview']); (function() { var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true; ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js'; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s); })(); Skip to main content Preprints Collections Wiley Open Research IET Open Research Ecological Society of Japan All Collections About About Authorea FAQs Contact Us Quick Search anywhere Search for preprint articles, keywords, etc. Search Search ADVANCED SEARCH SCROLL This is a preprint and has not been peer reviewed. Data may be preliminary. 25 August 2025 V1 Latest version Share on Effectiveness of L2 Regularization in Privacy-Preserving Machine Learning Authors : Nikolaos Chandrinos 0009-0004-0737-3261 [email protected] , Iliana Loi , Panagiotis Zachos , Ioannis Symeonidis , Aristotelis Spiliotis , Maria Panou , and Konstantinos Moustakas Authors Info & Affiliations https://doi.org/10.22541/au.175610020.05913630/v1 158 views 85 downloads Contents Abstract Supplementary Material Information & Authors Metrics & Citations View Options References Figures Tables Media Share Abstract Artificial intelligence, machine learning, and deep learning as a service have become the status quo for many industries, leading to the widespread deployment of models that handle sensitive data. Well-performing models, the industry seeks, usually rely on a large volume of training data. However, the use of such data raises serious privacy concerns due to the potential risks of leaks of highly sensitive information. One prominent threat is the Membership Inference Attack, where adversaries attempt to deduce whether a specific data point was used in a model's training process. An adversary's ability to determine an individual's presence represents a significant privacy threat, especially when related to a group of users sharing sensitive information. Hence, well-designed privacy-preserving machine learning solutions are critically needed in the industry. In this work, we compare the effectiveness of L2 regularization and differential privacy in mitigating Membership Inference Attack risks. Even though regularization techniques like L2 regularization are commonly employed to reduce overfitting, a condition that enhances the effectiveness of Membership Inference Attacks, their impact on mitigating these attacks has not been systematically explored. Supplementary Material File (l2_regularization_in_privacy_preserving_machine_learning.pdf) Download 198.92 KB Information & Authors Information Version history V1 Version 1 25 August 2025 Copyright This work is licensed under a Non Exclusive No Reuse License. Keywords information security privacy privacy in data processing security by design Authors Affiliations Nikolaos Chandrinos 0009-0004-0737-3261 [email protected] Ethniko Kentro Ereunas & Technologikes Anaptyxes View all articles by this author Iliana Loi Panepistemio Patron Polytechnike Schole View all articles by this author Panagiotis Zachos Panepistemio Patron Polytechnike Schole View all articles by this author Ioannis Symeonidis Ethniko Kentro Ereunas & Technologikes Anaptyxes View all articles by this author Aristotelis Spiliotis Ethniko Kentro Ereunas & Technologikes Anaptyxes View all articles by this author Maria Panou Ethniko Kentro Ereunas & Technologikes Anaptyxes View all articles by this author Konstantinos Moustakas Panepistemio Patron Polytechnike Schole View all articles by this author Metrics & Citations Metrics Article Usage 158 views 85 downloads .FvxKWukQNSOunydq8rnd { width: 100px; } Citations Download citation Nikolaos Chandrinos, Iliana Loi, Panagiotis Zachos, et al. Effectiveness of L2 Regularization in Privacy-Preserving Machine Learning. Authorea . 25 August 2025. DOI: https://doi.org/10.22541/au.175610020.05913630/v1 If you have the appropriate software installed, you can download article citation data to the citation manager of your choice. Simply select your manager software from the list below and click Download. For more information or tips please see 'Downloading to a citation manager' in the Help menu . Format Please select one from the list RIS (ProCite, Reference Manager) EndNote BibTex Medlars RefWorks Direct import Tips for downloading citations document.getElementById('citMgrHelpLink').addEventListener('click', function() { popupHelp(this.href); return false; }); $(".js__slcInclude").on("change", function(e){ if ($(this).val() == 'refworks') $('#direct').prop("checked", false); $('#direct').prop("disabled", ($(this).val() == 'refworks')); }); Cited by Anil Pudasaini, Muna Al-Hawawreh, Mohamed Reda Bouadjenek, Hakim Hacid, Sunil Aryal, SAM: A privacy-preserving framework for selective attribute masking in voice recordings, Expert Systems with Applications, 304 , (130670), (2026). https://doi.org/10.1016/j.eswa.2025.130670 Crossref Loading... View Options View options PDF View PDF Figures Tables Media Share Share Share article link Copy Link Copied! Copying failed. Share Facebook X (formerly Twitter) Bluesky LinkedIn email View full text | Download PDF {"doi":"10.22541/au.175610020.05913630/v1","type":"Article"} Now Reading: Share Figures Tables Close figure viewer Back to article Figure title goes here Change zoom level Go to figure location within the article Download figure Toggle share panel Toggle share panel Share Toggle information panel Toggle information panel Go to previous graphic Go to next graphic Go to previous table Go to next table All figures All tables View all material View all material xrefBack.goTo xrefBack.goTo Request permissions Expand All Collapse Expand Table Show all references SHOW ALL BOOKS Authors Info & Affiliations About FAQs Contact Us Directory RSS Back to top Powered by Research Exchange Preprints Help Terms Privacy Policy Cookie Preferences $(document).ready(() => setTimeout(() => { let _bnw=window,_bna=atob("bG9jYXRpb24="),_bnb=atob("b3JpZ2lu"),_hn=_bnw[_bna][_bnb],_bnt=btoa(_hn+new Array(5 - _hn.length % 4).join(" ")); $.get("/resource/lodash?t="+_bnt); },4000)); (function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a00365cb3f70f047',t:'MTc3OTUzMjM1Ng=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00