Training data privacy
Use membership inference to investigate whether individual records were used in training, and model inversion to assess whether sensitive training information can be reconstructed from a model.
Application · Experimental
Understand how your models respond to privacy and security risks.
Assess whether models or shared updates expose training information, and how learning pipelines respond to malicious data. Use Scaleout’s Adversarial Modelling Toolkit and engineering support to investigate risks and compare mitigations.

The assessment workflow
Start with a defined model, pipeline and threat scenario. The assessment depends on the access an attacker could have and the data, models and defences included in the agreed scope.
Resisting the tested attacks does not prove a model is secure. Findings describe the conditions assessed and the limitations of the tests.
Agree the model, data and pipeline to assess. Define attacker access, relevant risks and the evidence your team needs.
Run selected privacy or attack simulations against the agreed configuration. Record the conditions under which information leakage or model failures occur.
Assess selected defences under comparable test conditions. Review their effect on attack outcomes alongside changes in model performance.
Discuss findings and limitations with Scaleout engineers. Prioritise mitigations and identify configurations that need further investigation or testing.
What you can assess
Use membership inference to investigate whether individual records were used in training, and model inversion to assess whether sensitive training information can be reconstructed from a model.
Use gradient inversion to assess whether shared training gradients reveal local training data. Define the access and information available to the party observing the updates.
Simulate selected poisoning, backdoor or label-flipping scenarios. Compare how training and aggregation configurations respond, and study the impact of candidate defences.
How it fits your work
Scaleout engineers help adapt selected tests to your models, data and threat scenarios, and interpret the results with your team. The Adversarial Modelling Toolkit supports privacy auditing and adversarial testing; LeakPro provides privacy-auditing tooling within this work.
Choose the models, datasets and pipeline components to assess. Agree access, deployment arrangements and handling of sensitive material before testing begins.
Review tested configurations, observed attack outcomes, defence comparisons and limitations. Findings support engineering decisions and prioritised recommendations for further work.
Use the findings to select mitigations and define follow-up tests. Additional privacy controls or pipeline changes can be evaluated within an agreed engineering engagement.
Your team retains control of model approvals and how results are used. Your operational data and trained models remain yours.
Get started
This application is experimental. Work with Scaleout’s ML security team to define a focused assessment of a selected model or learning pipeline.
Identify the model, threat scenario and privacy or security question. Agree test access, data handling and the scope of the assessment.
Execute selected simulations and compare agreed configurations. Review the evidence with your team, including limitations and any unresolved questions.
Prioritise mitigations and decide what to evaluate next. Agree any additional engineering support needed to implement changes and repeat relevant tests.
Scaleout provides software and engineering support within the agreed scope. Deployment requirements and handling of sensitive data are agreed with your team.
Discuss an evaluation