Imprecise Probabilities for Privacy–Accuracy Trade-offs in Bayesian Networks

Niccol\textò Rocchi, Fabio Stella, Cassio de Campos
Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence, PMLR 337:5716-5730, 2026.

Abstract

{Bayesian} networks are well-known probabilistic graphical models that enable explainable reasoning under uncertainty. In many domains, data are scarce and fragmented across institutions, motivating collaboration and the sharing of learned models rather than individual-level records to increase the available evidence and reduce bias. Releasing a model, however, can still reveal sensitive information: adversaries may mount membership inference attacks to determine whether a specific individual contributed to the training. A common mitigation strategy is to inject noise into the learned model before its release. This perturbation may compromise the quality and interpretability of subsequent inferences. We investigate how a {Bayesian} network can be effectively masked rather than perturbed to protect it against attacks by leveraging credal networks, the imprecise version of {Bayesian} networks, allowing us to employ sets of parameters instead of exact point estimates. We formalize and compare various masking and attack strategies and investigate how privacy leakage depends on these strategies. Finally, we analyze how privacy and utility can be traded off in credal naive {Bayes} models, comparing them with the common noise-injection baseline. Results indicate that credal masking provides principled protection, substantially reducing attack success while yielding fine-tuned privacy-accuracy trade-offs.

Cite this Paper


BibTeX
@InProceedings{pmlr-v337-rocchi26a, title = {Imprecise Probabilities for Privacy–Accuracy Trade-offs in {Bayesian} Networks}, author = {Rocchi, Niccol\text{\`{o}} and Stella, Fabio and de Campos, Cassio}, booktitle = {Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence}, pages = {5716--5730}, year = {2026}, editor = {Perković, Emilija and Malinsky, Daniel}, volume = {337}, series = {Proceedings of Machine Learning Research}, month = {17--21 Aug}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v337/main/assets/rocchi26a/rocchi26a.pdf}, url = {https://proceedings.mlr.press/v337/rocchi26a.html}, abstract = {{Bayesian} networks are well-known probabilistic graphical models that enable explainable reasoning under uncertainty. In many domains, data are scarce and fragmented across institutions, motivating collaboration and the sharing of learned models rather than individual-level records to increase the available evidence and reduce bias. Releasing a model, however, can still reveal sensitive information: adversaries may mount membership inference attacks to determine whether a specific individual contributed to the training. A common mitigation strategy is to inject noise into the learned model before its release. This perturbation may compromise the quality and interpretability of subsequent inferences. We investigate how a {Bayesian} network can be effectively masked rather than perturbed to protect it against attacks by leveraging credal networks, the imprecise version of {Bayesian} networks, allowing us to employ sets of parameters instead of exact point estimates. We formalize and compare various masking and attack strategies and investigate how privacy leakage depends on these strategies. Finally, we analyze how privacy and utility can be traded off in credal naive {Bayes} models, comparing them with the common noise-injection baseline. Results indicate that credal masking provides principled protection, substantially reducing attack success while yielding fine-tuned privacy-accuracy trade-offs.} }
Endnote
%0 Conference Paper %T Imprecise Probabilities for Privacy–Accuracy Trade-offs in Bayesian Networks %A Niccol\textò Rocchi %A Fabio Stella %A Cassio de Campos %B Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence %C Proceedings of Machine Learning Research %D 2026 %E Emilija Perković %E Daniel Malinsky %F pmlr-v337-rocchi26a %I PMLR %P 5716--5730 %U https://proceedings.mlr.press/v337/rocchi26a.html %V 337 %X {Bayesian} networks are well-known probabilistic graphical models that enable explainable reasoning under uncertainty. In many domains, data are scarce and fragmented across institutions, motivating collaboration and the sharing of learned models rather than individual-level records to increase the available evidence and reduce bias. Releasing a model, however, can still reveal sensitive information: adversaries may mount membership inference attacks to determine whether a specific individual contributed to the training. A common mitigation strategy is to inject noise into the learned model before its release. This perturbation may compromise the quality and interpretability of subsequent inferences. We investigate how a {Bayesian} network can be effectively masked rather than perturbed to protect it against attacks by leveraging credal networks, the imprecise version of {Bayesian} networks, allowing us to employ sets of parameters instead of exact point estimates. We formalize and compare various masking and attack strategies and investigate how privacy leakage depends on these strategies. Finally, we analyze how privacy and utility can be traded off in credal naive {Bayes} models, comparing them with the common noise-injection baseline. Results indicate that credal masking provides principled protection, substantially reducing attack success while yielding fine-tuned privacy-accuracy trade-offs.
APA
Rocchi, N., Stella, F. & de Campos, C.. (2026). Imprecise Probabilities for Privacy–Accuracy Trade-offs in Bayesian Networks. Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence, in Proceedings of Machine Learning Research 337:5716-5730 Available from https://proceedings.mlr.press/v337/rocchi26a.html.

Related Material