HP-MIA: A novel membership inference attack scheme for high membership prediction precision

被引:1
|
作者
Chen, Shi [1 ]
Wang, Wennan [2 ]
Zhong, Yubin [1 ]
Ying, Zuobin [3 ]
Tang, Weixuan [4 ]
Pan, Zijie [4 ]
机构
[1] Guangzhou Univ, Sch Math & Informat Sci, Guangzhou, Peoples R China
[2] Xiamen Univ, Sch Econ, Xiamen, Peoples R China
[3] City Univ Macau, Fac Data Sci, Taipa, Macau, Peoples R China
[4] Guangzhou Univ, Inst Artificial Intelligence & Blockchain, Guangzhou, Peoples R China
基金
中国国家自然科学基金;
关键词
Machine learning; Deep learning; Privacy protection; Membership inference attack;
D O I
10.1016/j.cose.2023.103571
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Membership Inference Attacks (MIAs) have been considered as one of the major privacy threats in recent years, especially in machine learning models. Most canonical MIAs identify whether a specific data point was presented in the confidential training set of a neural network by analyzing its output pattern on such data point. However, these methods heavily rely on overfitting and are difficult to achieve high precision. Although some recent works, such as difficulty calibration techniques, have tried to tackle this problem in a tentative manner, identifying members with high precision is still a difficult task.To address above challenge, in this paper we rethink how overfitting impacts MIA and argue that it can provide much clearer signals of non-member samples. In scenarios where the cost of launching an attack is high, such signals can avoid unnecessary attacks and reduce the attack's false positive rate. Based on our observation, we propose High-Precision MIA (HP-MIA), a novel two-stage attack scheme that leverages membership exclusion techniques to guarantee high membership prediction precision. Our empirical results have illustrated that our two-stage attack can significantly increase the number of identified members while guaranteeing high precision.
引用
下载
收藏
页数:15
相关论文
共 50 条
  • [41] Understanding and defending against White-box membership inference attack in deep learning
    Wu, Di
    Qi, Saiyu
    Qi, Yong
    Li, Qian
    Cai, Bowen
    Guo, Qi
    Cheng, Jingxian
    KNOWLEDGE-BASED SYSTEMS, 2023, 259
  • [42] An Auto-Encoder based Membership Inference Attack against Generative Adversarial Network
    Azadmanesh, Maryam
    Ghahfarokhi, Behrouz Shahgholi
    Talouki, Maede Ashouri
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 15 (02): : 240 - 253
  • [43] Differential Privacy Protection Against Membership Inference Attack on Machine Learning for Genomic Data
    Chen, Junjie
    Wang, Wendy Hui
    Shi, Xinghua
    PACIFIC SYMPOSIUM ON BICOMPUTING 2021, 2021, : 26 - 37
  • [44] Subject-Level Membership Inference Attack via Data Augmentation and Model Discrepancy
    Liu, Yimin
    Jiang, Peng
    Zhu, Liehuang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5848 - 5859
  • [45] Membership Inference Attacks Against Machine Learning Models via Prediction Sensitivity
    Liu, Lan
    Wang, Yi
    Liu, Gaoyang
    Peng, Kai
    Wang, Chen
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2341 - 2347
  • [46] Defending Against Membership Inference Attack for Counterfactual Federated Recommendation With Differentially Private Representation Learning
    Liu, Xiuwen
    Chen, Yanjiao
    Pang, Shanchen
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 8037 - 8051
  • [47] A Novel Multi Membership Function Based VLSI Architecture of a Fuzzy Inference Processor
    Loan, Sajad A.
    Murshid, Asim M.
    Abbasi, Shuja A.
    Alamoud, Abdul Rahman M.
    INTERNATIONAL JOURNAL OF FUZZY SYSTEMS, 2014, 16 (04) : 468 - 482
  • [48] Mitigating Membership Inference in Deep Learning Applications with High Dimensional Genomic Data
    Zhang, Chonghao
    Bonomi, Luca
    2022 IEEE 10TH INTERNATIONAL CONFERENCE ON HEALTHCARE INFORMATICS (ICHI 2022), 2022, : 534 - 536
  • [49] Mitigating Membership Inference Attacks by Self-Distillation Through a Novel Ensemble Architecture
    Tang, Xinyu
    Mahloujifar, Saeed
    Song, Liwei
    Shejwalkar, Virat
    Nasr, Milad
    Houmansadr, Amir
    Mittal, Prateek
    PROCEEDINGS OF THE 31ST USENIX SECURITY SYMPOSIUM, 2022, : 1433 - 1450
  • [50] A novel VLSI architecture for a fuzzy inference processor using Gaussian-shaped membership function
    Loan, Sajad A.
    Murshid, Asim M.
    Abbasi, Shuja A.
    Alamoud, Abdul Rahman M.
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2013, 24 (01) : 5 - 19