The Attention Concentration Score (ACS) is introduced, which measures how DP training shifts Transformer attention away from task-critical features toward non-functional ones, providing a mechanistic explanation of the trade-off.
Abstract
AI models in critical sectors such as healthcare and finance must provide both data privacy and adversarial robustness. Differential Privacy (DP) protects training data by injecting noise, but this noise smooths decision boundaries and leaves models open to adversarial evasion, a tension known as the Privacy-Robustness Trade-off. Although this trade-off is well documented, its internal mechanism remains underexplored: prior work does not reveal how the noise reshapes a model’s reasoning or which features become vulnerable. To close this gap, we propose a Privacy-Aware Adversarial Defense grounded in Explainable AI. Specifically, we introduce the Attention Concentration Score (ACS), which measures how DP training shifts Transformer attention away from task-critical features toward non-functional ones. This attention drift correlates with adversarial vulnerability, providing a mechanistic explanation of the trade-off. Building on this insight, we develop a Manifold-Aligned Semantic Attack that targets the most drifted features, and a TrustScore defense that fuses embedding-level anomaly detection with attention-level consistency checks. We validate across two datasets (Adult Census, MIMIC-IV), two architectures (DeBERTa-V3-Large, LLaMA−3.1-8B), and seven experiments benchmarking five attacks against six defenses. Within the recommended range (ϵ∈[5,10]\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$\epsilon \in [5, 10]$$\end{document}), models retain 84.2% accuracy (96.2% of baseline), while TrustScore reaches an Area Under the ROC Curve (AUC) of 0.87-−0.94, outperforming Isolation Forest (0.65) and supervised detection (0.58). Moreover, these conclusions hold under feature-categorization variants (attribution- and PCA-based); privacy noise disproportionately destabilizes the minority class; the consistency signal adds sub-millisecond overhead; and a surrogate-attention variant preserves detection under black-box deployment, establishing the approach’s dependability for reliable intelligent environments.
Mitigating Attacks on LLMs with Privacy and Adversarial TrainingOlasunkanmi Sodunke
School of Engineering Technology, Purdue University The rapid adoption of Large Language Models (LLMs) such as BERT & GPT-3 has intensified privacy concerns, especially with vulnerabilities like model inversion and membership inference...
Current adversarial defense methods often rely on specific perturbation generation techniques, which face challenges such as limited generalization performance and high computational costs. This paper addresses these issues by examining the response characteristics of intelligent learning models to sensitive adversaria...
Qian Li, Di Wu, Saiyu Qi et al.· International Conference on...· 0 citations
A novel framework for adversarial machine unlearning is introduced to enable privacy-preserving threat intelligence sharing and lays the foundation for secure and compliant knowledge transfer in federated security operations and collaborative defence ecosystems.
R. Polishetty· Journal of Intelligent Decis...· 0 citations
Continual learning (CL) is a key paradigm that enables intelligent agents to operate autonomously in edge networks over the long term. However, continuous model updates can lead to catastrophic forgetting and representation instability in edge deployment scenarios, which may further induce Decision Boundary Drift (DBD)...
Kai-Xiang Yang, Yue-Bin Xu, Zhi-Hao Li et al.· IEEE Transactions on Network...· 0 citations
This paper presents a systematic framework for membership inference attacks, in which an adversary with only black-box query access to a deployed classifier determines whether a specific individual's record was part of its training set.
Pramod Prakash· International Journal of Int...· 0 citations
A structural causal model (SCM) is introduced that generates a realistically grounded, labelled dataset of user-sessions, with coordinated multi-account campaigns, platform feedback, and three tiers of label observability.
Keifer Lee· 0 citations
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 8, 2026
Exploring how generative AI could make machine vision more accessible to businesses. The post GenEye in a Box: Making Machine Vision Something You Can Just Ask For appeared first on GPT-Lab.
MIT News · Artificial Intelligence· news.mit.eduOct 8, 2026
Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.