Your browser doesn't support javascript. This means that the content or functionality of our website will be limited or unavailable. If you need more information about Vinnova, please contact us.

Our e-services for applications, projects and assessments close on Thursday 23 January at 4:30pm because of system upgrades. We expect to open them again on Friday 24 January at 8am the latest.

LEAKPRO: Leakage Profiling and Risk Oversight for Machine Learning Models

Reference number
Coordinator Lindholmen Science Park AB - AI Sweden
Funding from Vinnova SEK 9 999 968
Project duration November 2023 - November 2025
Status Ongoing
Venture Advanced digitalization - Enabling technologies
Call Cyber security for industrial advanced digitalization 2023

Purpose and goal

The primary goal is to create LEAKPRO, a platform to evaluate the risk of information leakage in machine learning applications and to identify/validate realistic attack vectors. LEAKPRO will be developed as open-source with a focus on scalability and relevance. Attacks against different types of model architectures and data modalities will be supported to be as relevant as possible to the Swedish ecosystem. LEAKPRO supports risk profiling of data leakage for different types of scenarios such as black-box, white-box, federated training, and synthetic data.

Expected effects and result

LEAKPRO is expected to assist the Swedish ecosystem with a tool to responsibly expose machine learning models and synthetic data to external parties. LEAKPRO will act as a component in the development chain to iterate a model that minimizes the risk of data leakage given current state-of-the-art attacks. Furthermore, LEAKPRO is expected to contribute to political discussions as a basis to assess the real risks regarding the overlap between secrecy and machine learning models.

Planned approach and implementation

LEAKPRO is divided into seven work packages. The first package focuses on establishing an architecture for the platform. Work packages 2-5 happen in parallel where attacks are implemented and tested against 1) white/black-box models, 2) federated learning, 3) synthetic data. Work package 5 aims to implement the attacks in LEAKPRO along with tests and documentation. Work package 6 is about testing LEAKPRO internally with project partners and paving the way for inclusion in RISE Cyberrange. Work package 7 deals with knowledge sharing and administration.

The project description has been provided by the project members themselves and the text has not been looked at by our editors.

Last updated 15 November 2023

Reference number 2023-03000