๐ฏ What is privacylens?
Most ML engineers don't know if their model is leaking private training data. privacylens audits it.
from privacylens import audit
report = audit(model, X_train, y_train, X_test)
report.summary()
# Export HTML Compliance Report for GDPR/HIPAA sharing
report.to_html("audit_report.html")
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๐ privacylens โ Privacy Audit Report โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโค
โ Check โ Score โ Risk โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโค
โ Membership Inference Attack โ 0.087 โ LOW โ
โ PII Leakage Detection โ 0.000 โ LOW โ
โ Model Inversion Risk โ 0.042 โ LOW โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโ
Model: RandomForestClassifier
Overall Risk: LOW
โข MIA advantage score: 0.087 โ model shows low Membership Inference vulnerability.
โข PII leakage score: 0.000 โ model shows low PII Leakage vulnerability.
โข Model Inversion score: 0.042 โ model shows low Model Inversion vulnerability.
โจ Features
- ๐ต๏ธ Membership Inference Attack (MIA) โ Detect if an attacker can identify training records using shadow model estimation (Shokri et al., 2017)
- ๐ PII Leakage Detection โ Detect sensitive PII (Emails, SSNs, Credit Cards, Phones, IPs) memorized in predictions or samples
- ๐ Model Inversion Risk Scorer โ Evaluate feature reconstructability risk from output confidence probabilities (Fredrikson et al., 2015)
- ๐ Native Framework Adapters โ Out-of-the-box support for scikit-learn, PyTorch (
nn.Module), and XGBoost models - ๐ HTML Compliance Reports โ Export standalone, interactive HTML reports (
--report audit.html) for security & GDPR/HIPAA compliance sharing - ๐จ Beautiful terminal output โ Rich colour-coded risk tables with LOW / MEDIUM / HIGH classification
- ๐ค CLI + Python API โ Use in scripts or integrate into CI/CD pipelines (
privacylens audit) - ๐ JSON output โ Machine-readable results for dashboards and reporting (
--output json)
Coming in v1.0.0:
- ๐ค HuggingFace Transformers LLM adapter
- ๐ Enterprise Privacy Benchmark Suite
๐ฆ Installation
# Base install (scikit-learn models)
pip install privacyaudit
# With PyTorch support
pip install "privacyaudit[torch]"
# With XGBoost support
pip install "privacyaudit[xgboost]"
# Everything
pip install "privacyaudit[all]"
Note: The PyPI package is
privacyaudit. Import in Python asfrom privacylens import audit.
๐ Quick Start
from sklearn.ensemble import RandomForestClassifier
from sklearn.datasets import make_classification
from sklearn.model_selection import train_test_split
from privacylens import audit
# Train a model
X, y = make_classification(n_samples=1000, n_features=20, random_state=42)
X_train, X_test, y_train, y_test = train_test_split(X, y, test_size=0.3)
model = RandomForestClassifier(n_estimators=100)
model.fit(X_train, y_train)
# Audit it for privacy vulnerabilities (MIA + PII Leakage + Model Inversion)
report = audit(model, X_train, y_train, X_test, y_test)
report.summary()
# Export interactive HTML audit report
report.to_html("compliance_report.html")
# Get audit results as dict (for JSON logging or API responses)
print(report.to_dict())
๐ฅ๏ธ CLI Usage
# Audit a saved model file
privacylens audit model.pkl train.csv test.csv
# Export interactive HTML report
privacylens audit model.pkl train.csv test.csv --report compliance.html
# Output JSON for CI/CD integration
privacylens audit model.pkl train.csv test.csv --output json
# Skip MIA check in fast pipelines
privacylens audit model.pkl train.csv test.csv --no-mia
๐๏ธ Architecture
privacylens/
โโโ src/privacylens/
โ โโโ __init__.py # Public API: audit(), AuditReport, Auditors, Adapters
โ โโโ auditor.py # Core orchestrator
โ โโโ adapters/
โ โ โโโ base.py # BaseModelAdapter & get_adapter() factory
โ โ โโโ sklearn_adapter.py
โ โ โโโ pytorch_adapter.py
โ โ โโโ xgboost_adapter.py
โ โโโ attacks/
โ โ โโโ membership.py # MIA engine (shadow model + attack classifier)
โ โ โโโ inversion.py # Model Inversion Risk Auditor (Fredrikson et al.)
โ โโโ leakage/
โ โ โโโ pii.py # PII Leakage Auditor (Regex + Severity Weighting)
โ โโโ report/
โ โ โโโ html.py # HTML Compliance Report Generator (Jinja2)
โ โโโ cli.py # Click CLI
โโโ tests/
โโโ test_auditor.py
โโโ test_membership.py
โโโ test_pii_leakage.py
โโโ test_inversion.py
โโโ test_adapters.py
โโโ test_html_report.py
๐ Risk Score Interpretation
| Check Score | Risk Level | Meaning |
|---|---|---|
0.0 โ 0.10 |
๐ข LOW | Model reveals minimal membership/PII/inversion information |
0.10 โ 0.30 |
๐ก MEDIUM | Moderate risk โ review training data exposure |
0.30 โ 1.00 |
๐ด HIGH | Model likely memorising sensitive training data |
๐ค Contributing
See CONTRIBUTING.md. All contributions welcome!
๐ License
MIT โ see LICENSE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file privacyaudit-0.5.0.tar.gz.
File metadata
- Download URL: privacyaudit-0.5.0.tar.gz
- Upload date:
- Size: 18.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7c98d8a0fc56aba1d3845c1e475f64a1cc7c529fba4a1f6bde0264ad4b6d047a
|
|
| MD5 |
ada3421b1e74ad75abd4eb998bbec9a8
|
|
| BLAKE2b-256 |
ffcd5f0113434dd1f9459112650b24f80b0498cc4305fe34710fe62559a462bc
|
Provenance
The following attestation bundles were made for privacyaudit-0.5.0.tar.gz:
Publisher:
release.yml on nithin42/privacylens
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
privacyaudit-0.5.0.tar.gz -
Subject digest:
7c98d8a0fc56aba1d3845c1e475f64a1cc7c529fba4a1f6bde0264ad4b6d047a - Sigstore transparency entry: 2306945330
- Sigstore integration time:
-
Permalink:
nithin42/privacylens@87886f85b45919274c9cd020e13a834805afb5b5 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/nithin42
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@87886f85b45919274c9cd020e13a834805afb5b5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file privacyaudit-0.5.0-py3-none-any.whl.
File metadata
- Download URL: privacyaudit-0.5.0-py3-none-any.whl
- Upload date:
- Size: 20.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
bc7e7392942af9cb83f14d84dd30419b1e6dc7a6f2864ec0a5c7033783e87a66
|
|
| MD5 |
33a318919601ee10e48dc79c9baaf32d
|
|
| BLAKE2b-256 |
4a706f5e4689b898f2e86a166af9d62aacbd6ebba34c775f4ff343acf4d9d80c
|
Provenance
The following attestation bundles were made for privacyaudit-0.5.0-py3-none-any.whl:
Publisher:
release.yml on nithin42/privacylens
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
privacyaudit-0.5.0-py3-none-any.whl -
Subject digest:
bc7e7392942af9cb83f14d84dd30419b1e6dc7a6f2864ec0a5c7033783e87a66 - Sigstore transparency entry: 2306945347
- Sigstore integration time:
-
Permalink:
nithin42/privacylens@87886f85b45919274c9cd020e13a834805afb5b5 -
Branch / Tag:
refs/tags/v0.5.0 - Owner: https://github.com/nithin42
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@87886f85b45919274c9cd020e13a834805afb5b5 -
Trigger Event:
push
-
Statement type: