Skip to main content

๐Ÿ” privacylens

Audit any ML model for privacy vulnerabilities โ€” in 3 lines of code.

CI Coverage PyPI version Python Discussions License: MIT PRs Welcome


๐ŸŽฏ What is privacylens?

Most ML engineers don't know if their model is leaking private training data. privacylens audits it.

from privacylens import audit

report = audit(model, X_train, y_train, X_test)
report.summary()
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚             ๐Ÿ” privacylens โ€” Privacy Audit Report            โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Check                        โ”‚ Score      โ”‚ Risk            โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ Membership Inference Attack  โ”‚ 0.087      โ”‚ LOW             โ”‚
โ”‚ PII Leakage Detection        โ”‚ 0.000      โ”‚ LOW             โ”‚
โ”‚ Model Inversion Risk         โ”‚ 0.042      โ”‚ LOW             โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Model: RandomForestClassifier
Overall Risk: LOW

โ€ข MIA advantage score: 0.087 โ€” model shows low Membership Inference vulnerability.
โ€ข PII leakage score: 0.000 โ€” model shows low PII Leakage vulnerability.
โ€ข Model Inversion score: 0.042 โ€” model shows low Model Inversion vulnerability.

โœจ Features

  • ๐Ÿ•ต๏ธ Membership Inference Attack (MIA) โ€” Detect if an attacker can identify training records using shadow model estimation (Shokri et al., 2017)
  • ๐Ÿ”Ž PII Leakage Detection โ€” Detect sensitive PII (Emails, SSNs, Credit Cards, Phones, IPs) memorized in predictions or samples
  • ๐Ÿ”„ Model Inversion Risk Scorer โ€” Evaluate feature reconstructability risk from output confidence probabilities (Fredrikson et al., 2015)
  • ๐ŸŒ Native Framework Adapters โ€” Out-of-the-box support for scikit-learn, PyTorch (nn.Module), and XGBoost models
  • ๐ŸŽจ Beautiful terminal output โ€” Rich colour-coded risk tables with LOW / MEDIUM / HIGH classification
  • ๐Ÿค– CLI + Python API โ€” Use in scripts or integrate into CI/CD pipelines (privacylens audit)
  • ๐Ÿ“Š JSON output โ€” Machine-readable results for dashboards and reporting (--output json)

Coming in future releases:

  • ๐Ÿ“„ HTML compliance report export (Jinja2) for GDPR/HIPAA auditing
  • ๐Ÿค— HuggingFace Transformers LLM adapter

๐Ÿ“ฆ Installation

# Base install (scikit-learn models)
pip install privacyaudit

# With PyTorch support
pip install "privacyaudit[torch]"

# With XGBoost support
pip install "privacyaudit[xgboost]"

# Everything
pip install "privacyaudit[all]"

Note: The PyPI package is privacyaudit. Import in Python as from privacylens import audit.


๐Ÿš€ Quick Start

from sklearn.ensemble import RandomForestClassifier
from sklearn.datasets import make_classification
from sklearn.model_selection import train_test_split
from privacylens import audit

# Train a model
X, y = make_classification(n_samples=1000, n_features=20, random_state=42)
X_train, X_test, y_train, y_test = train_test_split(X, y, test_size=0.3)

model = RandomForestClassifier(n_estimators=100)
model.fit(X_train, y_train)

# Audit it for privacy vulnerabilities (MIA + PII Leakage + Model Inversion)
report = audit(model, X_train, y_train, X_test, y_test)
report.summary()

# Get audit results as dict (for JSON logging or API responses)
print(report.to_dict())

๐Ÿ–ฅ๏ธ CLI Usage

# Audit a saved model file
privacylens audit model.pkl train.csv test.csv

# Output JSON for CI/CD integration
privacylens audit model.pkl train.csv test.csv --output json

# Skip MIA check in fast pipelines
privacylens audit model.pkl train.csv test.csv --no-mia

๐Ÿ—๏ธ Architecture

privacylens/
โ”œโ”€โ”€ src/privacylens/
โ”‚   โ”œโ”€โ”€ __init__.py         # Public API: audit(), AuditReport, Auditors, Adapters
โ”‚   โ”œโ”€โ”€ auditor.py          # Core orchestrator
โ”‚   โ”œโ”€โ”€ adapters/
โ”‚   โ”‚   โ”œโ”€โ”€ base.py         # BaseModelAdapter & get_adapter() factory
โ”‚   โ”‚   โ”œโ”€โ”€ sklearn_adapter.py
โ”‚   โ”‚   โ”œโ”€โ”€ pytorch_adapter.py
โ”‚   โ”‚   โ””โ”€โ”€ xgboost_adapter.py
โ”‚   โ”œโ”€โ”€ attacks/
โ”‚   โ”‚   โ”œโ”€โ”€ membership.py   # MIA engine (shadow model + attack classifier)
โ”‚   โ”‚   โ””โ”€โ”€ inversion.py    # Model Inversion Risk Auditor (Fredrikson et al.)
โ”‚   โ”œโ”€โ”€ leakage/
โ”‚   โ”‚   โ””โ”€โ”€ pii.py          # PII Leakage Auditor (Regex + Severity Weighting)
โ”‚   โ””โ”€โ”€ cli.py              # Click CLI
โ””โ”€โ”€ tests/
    โ”œโ”€โ”€ test_auditor.py
    โ”œโ”€โ”€ test_membership.py
    โ”œโ”€โ”€ test_pii_leakage.py
    โ”œโ”€โ”€ test_inversion.py
    โ””โ”€โ”€ test_adapters.py

๐Ÿ“– Risk Score Interpretation

Check Score Risk Level Meaning
0.0 โ€“ 0.10 ๐ŸŸข LOW Model reveals minimal membership/PII/inversion information
0.10 โ€“ 0.30 ๐ŸŸก MEDIUM Moderate risk โ€” review training data exposure
0.30 โ€“ 1.00 ๐Ÿ”ด HIGH Model likely memorising sensitive training data

๐Ÿค Contributing

See CONTRIBUTING.md. All contributions welcome!

๐Ÿ“„ License

MIT โ€” see LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

privacyaudit-0.4.0.tar.gz (15.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

privacyaudit-0.4.0-py3-none-any.whl (17.7 kB view details)

Uploaded Python 3

File details

Details for the file privacyaudit-0.4.0.tar.gz.

File metadata

  • Download URL: privacyaudit-0.4.0.tar.gz
  • Upload date:
  • Size: 15.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for privacyaudit-0.4.0.tar.gz
Algorithm Hash digest
SHA256 6c1b8d2998591d7d48eb1b96fd4b3f3782529cca268e4da0d2fc0cf84cadb70c
MD5 369903d81fd5ae651acd127224bee87c
BLAKE2b-256 d1b99ba104ac21e1718c988aee031f264aba9e5e4be989de1b31206a0d2b317a

See more details on using hashes here.

Provenance

The following attestation bundles were made for privacyaudit-0.4.0.tar.gz:

Publisher: release.yml on nithin42/privacylens

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file privacyaudit-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: privacyaudit-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 17.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for privacyaudit-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 cdabda3ba30cf453462747da64fc30404896bf51b8e9b3967af956b2fd9674ba
MD5 6c9a7c3378e134700ad4864f3f41b71c
BLAKE2b-256 4a922030b0a7abb6dfa605087746c2125eb162457a5ebef33aa77df168f6f984

See more details on using hashes here.

Provenance

The following attestation bundles were made for privacyaudit-0.4.0-py3-none-any.whl:

Publisher: release.yml on nithin42/privacylens

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page