Skip to main content
Guidance

Machine learning principles

These principles help developers, engineers, decision makers and risk owners make informed decisions about the design, development, deployment and operation of their machine learning (ML) systems.

Page 17 of 22

4.2 Appropriately sanitise inputs to your model in use



What happens to filtered data will depend on the application and it will likely need regular review by humans. Filters will also need regular review and may need updates if adversaries find ways to bypass them.

Implement out of distribution detection on model inputs

Your development team should choose the best OoD detection for your application. Options include using maximum softmax probability and temperature scaling. If you have a complex model with large feature spaces that are OoD, it may be worth exploring whether you can factor the OoD distance into the model’s confidence scores. In some cases, this could act as detection mechanism for adversarial attacks. Further information on OoD detection can be found in this article from Encord.

Use appropriate techniques to anonymise user data

This allows you to collect data while protecting privacy, reducing security concerns. Data anonymisation techniques include:

  • Differential privacy: using statistical techniques to ensure privacy without affecting the dataset's overall statistical integrity.

  • Data masking: a range of techniques that represent a point in a different way that’s usually unreadable to a human, such as encryption, hashing or data obfuscation.

  • Generalisation/aggregation: 'zooming out' of the data to anonymise individual contributions while keeping overall trends.

  • Data swapping: swapping attributes/data points between entries while maintaining the underlying statistics of the dataset.

  • Pseudonymisation: removing (and keeping separate) attributes of the data such that a data point can no longer be attributed to a specific entry without the removed information.

Published

Reviewed

Version

2.0