Defending Privacy Against More Knowledgeable Membership Inference Attackers

被引:7
|
作者
Yin, Yu [1 ]
Chen, Ke
Shou, Lidan
Chen, Gang
机构
[1] Zhejiang Univ, State Key Lab CAD&CG, Hangzhou, Zhejiang, Peoples R China
关键词
Privacy; Membership inference attack; Crystal-box;
D O I
10.1145/3447548.3467444
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Membership Inference Attack (MIA) in deep learning is a common form of privacy attack which aims to infer whether a data sample is in a target classifier's training dataset or not. Previous studies of MIA typically tackle either a black-box or a white-box adversary model, assuming an attacker not knowing (or knowing) the structure and parameters of the target classifier while having access to the confidence vector of the query output. With the popularity of privacy protection methods such as differential privacy, it is increasingly easier for an attacker to obtain the defense method adopted by the target classifier, which poses extra challenge to privacy protection. In this paper, we name such attacker a crystal-box adversary. We present definitions for utility and privacy of target classifier, and formulate the design goal of the defense method as an optimization problem. We also conduct theoretical analysis on the respective forms of the optimization for three adversary models, namely black-box, white-box, and crystal-box, and prove that the optimization problem is NP-hard. Thereby we solve a surrogate problem and propose three defense methods, which, if used together, can make trade-off between utility and privacy. A notable advantage of our approach is that it can be used to resist attacks from three adversary models, namely black-box, white-box, and crystal-box, simultaneously. Evaluation results show effectiveness of our proposed approach for defending privacy against MIA and better performance compared to previous defense methods.
引用
收藏
页码:2026 / 2036
页数:11
相关论文
共 50 条
  • [1] Defending Against Membership Inference Attack by Shielding Membership Signals
    Miao, Yinbin
    Yu, Yueming
    Li, Xinghua
    Guo, Yu
    Liu, Ximeng
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (06) : 4087 - 4101
  • [2] BAN-MPR: Defending against Membership Inference Attacks with Born Again Networks and Membership Privacy Regularization
    Liu, Yiqing
    Yu, Juan
    Han, Jianmin
    [J]. 2022 INTERNATIONAL CONFERENCE ON COMPUTERS AND ARTIFICIAL INTELLIGENCE TECHNOLOGIES, CAIT, 2022, : 9 - 15
  • [3] Defending Against Membership Inference Attacks on Beacon Services
    Venkatesaramani, Rajagopal
    Wan, Zhiyu
    Malin, Bradley A.
    Vorobeychik, Yevgeniy
    [J]. ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (03)
  • [4] Defending Against Membership Inference Attacks With High Utility by GAN
    Hu, Li
    Li, Jin
    Lin, Guanbiao
    Peng, Shiyu
    Zhang, Zhenxin
    Zhang, Yingying
    Dong, Changyu
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2144 - 2157
  • [5] Defending against multiple different attackers
    Hausken, Kjell
    Bier, Vicki M.
    [J]. EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2011, 211 (02) : 370 - 384
  • [6] Preserving Privacy in GANs Against Membership Inference Attack
    Shateri, Mohammadhadi
    Messina, Francisco
    Labeau, Fabrice
    Piantanida, Pablo
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1728 - 1743
  • [7] Strategies for Defending a Coastline Against Multiple Attackers
    Garcia, Eloy
    Von Moll, Alexander
    Casbeer, David W.
    Pachter, Meir
    [J]. 2019 IEEE 58TH CONFERENCE ON DECISION AND CONTROL (CDC), 2019, : 7319 - 7324
  • [8] Defending against membership inference attacks: RM Learning is all you need
    Zhang, Zheng
    Ma, Jianfeng
    Ma, Xindi
    Yang, Ruikang
    Wang, Xiangyu
    Zhang, Junying
    [J]. INFORMATION SCIENCES, 2024, 670
  • [9] Defending against Membership Inference Attacks in Federated learning via Adversarial Example
    Xie, Yuanyuan
    Chen, Bing
    Zhang, Jiale
    Wu, Di
    [J]. 2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 153 - 160
  • [10] Gaussian Membership Inference Privacy
    Leemann, Tobias
    Pawelczyk, Martin
    Kasneci, Gjergji
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,