Related Experiment Video
Updated: Feb 3, 2026

Inverse Probability of Treatment Weighting Propensity Score using the Military Health System Data Repository and National Death Index
Published on: January 8, 2020
Algorithms that remember: model inversion attacks and data protection law
Michael Veale1, Reuben Binns2, Lilian Edwards3
1Department of Science, Technology, Engineering and Public Policy, University College London, London, UK m.veale@ucl.ac.uk.
Abstract:
Many individuals are concerned about the governance of machine learning systems and the prevention of algorithmic harms. The EU's recent General Data Protection Regulation (GDPR) has been seen as a core tool for achieving better governance of this area. While the GDPR does apply to the use of models in some limited situations, most of its provisions relate to the governance of personal data, while models have traditionally been seen as intellectual property. We present recent work from the information security literature around 'model inversion' and 'membership inference' attacks, which indicates that the process of turning training data into machine-learned systems is not one way, and demonstrate how this could lead some models to be legally classified as personal data. Taking this as a probing experiment, we explore the different rights and obligations this would trigger and their utility, and posit future directions for algorithmic governance and regulation.This article is part of the theme issue 'Governing artificial intelligence: ethical, legal, and technical opportunities and challenges'.
Related Concept Videos
Second Law of Thermodynamics
The Integrated Rate Law: The Dependence of Concentration on Time
Acid Attack on Concrete
The rate at which hydrogen...
Gas Laws: Boyle's, Gay-Lussac, Charles', Avogadro's, and Ideal Gas Law
Scientific Laws and Theories
Mechanistic Models: Compartment Models in Algorithms for Numerical Problem Solving
In individual population analyses, different algorithms are employed, such as Cauchy's method, which uses a...

