HP-MIA: A novel membership inference attack scheme for high membership prediction precision

被引:1
|
作者
Chen, Shi [1 ]
Wang, Wennan [2 ]
Zhong, Yubin [1 ]
Ying, Zuobin [3 ]
Tang, Weixuan [4 ]
Pan, Zijie [4 ]
机构
[1] Guangzhou Univ, Sch Math & Informat Sci, Guangzhou, Peoples R China
[2] Xiamen Univ, Sch Econ, Xiamen, Peoples R China
[3] City Univ Macau, Fac Data Sci, Taipa, Macau, Peoples R China
[4] Guangzhou Univ, Inst Artificial Intelligence & Blockchain, Guangzhou, Peoples R China
基金
中国国家自然科学基金;
关键词
Machine learning; Deep learning; Privacy protection; Membership inference attack;
D O I
10.1016/j.cose.2023.103571
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Membership Inference Attacks (MIAs) have been considered as one of the major privacy threats in recent years, especially in machine learning models. Most canonical MIAs identify whether a specific data point was presented in the confidential training set of a neural network by analyzing its output pattern on such data point. However, these methods heavily rely on overfitting and are difficult to achieve high precision. Although some recent works, such as difficulty calibration techniques, have tried to tackle this problem in a tentative manner, identifying members with high precision is still a difficult task.To address above challenge, in this paper we rethink how overfitting impacts MIA and argue that it can provide much clearer signals of non-member samples. In scenarios where the cost of launching an attack is high, such signals can avoid unnecessary attacks and reduce the attack's false positive rate. Based on our observation, we propose High-Precision MIA (HP-MIA), a novel two-stage attack scheme that leverages membership exclusion techniques to guarantee high membership prediction precision. Our empirical results have illustrated that our two-stage attack can significantly increase the number of identified members while guaranteeing high precision.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] CS-MIA: Membership inference attack based on prediction confidence series in federated learning
    Gu, Yuhao
    Bai, Yuebin
    Xu, Shubin
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 67
  • [2] Demystifying the Membership Inference Attack
    Irolla, Paul
    Chatel, Gregory
    [J]. 2019 12TH CMI CONFERENCE ON CYBERSECURITY AND PRIVACY (CMI), 2019, : 1 - 7
  • [3] Defending Against Membership Inference Attack by Shielding Membership Signals
    Miao, Yinbin
    Yu, Yueming
    Li, Xinghua
    Guo, Yu
    Liu, Ximeng
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (06) : 4087 - 4101
  • [4] FP2-MIA: A Membership Inference Attack Free of Posterior Probability in Machine Unlearning
    Lu, Zhaobo
    Wang, Yilei
    Lv, Qingzhe
    Zhao, Minghao
    Liang, Tiancai
    [J]. PROVABLE AND PRACTICAL SECURITY, PROVSEC 2022, 2022, 13600 : 167 - 175
  • [5] Membership inference attack for beluga whales discrimination
    Araujo, Voncarlos M.
    Gambs, Sebastien
    Michaud, Robert
    Lautraite, Hadrien
    Schneider, Leo
    Chion, Clement
    [J]. ECOLOGICAL INFORMATICS, 2024, 79
  • [6] Membership Inference Attack on Graph Neural Networks
    Olatunji, Iyiola E.
    Nejdl, Wolfgang
    Khosla, Megha
    [J]. 2021 THIRD IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2021), 2021, : 11 - 20
  • [7] Membership Inference Attack in Face of Data Transformations
    Chen, Jiyu
    Guo, Yiwen
    Chen, Hao
    Gong, Neil
    [J]. 2022 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2022, : 299 - 307
  • [8] Preserving Privacy in GANs Against Membership Inference Attack
    Shateri, Mohammadhadi
    Messina, Francisco
    Labeau, Fabrice
    Piantanida, Pablo
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1728 - 1743
  • [9] Membership Inference Attack Against Principal Component Analysis
    Zari, Oualid
    Parra-Arnau, Javier
    Unsal, Ayse
    Strufe, Thorsten
    Onen, Melek
    [J]. PRIVACY IN STATISTICAL DATABASES, PSD 2022, 2022, 13463 : 269 - 282
  • [10] Practical Membership Inference Attack Against Collaborative Inference in Industrial IoT
    Chen, Hanxiao
    Li, Hongwei
    Dong, Guishan
    Hao, Meng
    Xu, Guowen
    Huang, Xiaoming
    Liu, Zhe
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (01) : 477 - 487