Defending Privacy Against More Knowledgeable Membership Inference Attackers

被引:7
|
作者
Yin, Yu [1 ]
Chen, Ke
Shou, Lidan
Chen, Gang
机构
[1] Zhejiang Univ, State Key Lab CAD&CG, Hangzhou, Zhejiang, Peoples R China
关键词
Privacy; Membership inference attack; Crystal-box;
D O I
10.1145/3447548.3467444
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Membership Inference Attack (MIA) in deep learning is a common form of privacy attack which aims to infer whether a data sample is in a target classifier's training dataset or not. Previous studies of MIA typically tackle either a black-box or a white-box adversary model, assuming an attacker not knowing (or knowing) the structure and parameters of the target classifier while having access to the confidence vector of the query output. With the popularity of privacy protection methods such as differential privacy, it is increasingly easier for an attacker to obtain the defense method adopted by the target classifier, which poses extra challenge to privacy protection. In this paper, we name such attacker a crystal-box adversary. We present definitions for utility and privacy of target classifier, and formulate the design goal of the defense method as an optimization problem. We also conduct theoretical analysis on the respective forms of the optimization for three adversary models, namely black-box, white-box, and crystal-box, and prove that the optimization problem is NP-hard. Thereby we solve a surrogate problem and propose three defense methods, which, if used together, can make trade-off between utility and privacy. A notable advantage of our approach is that it can be used to resist attacks from three adversary models, namely black-box, white-box, and crystal-box, simultaneously. Evaluation results show effectiveness of our proposed approach for defending privacy against MIA and better performance compared to previous defense methods.
引用
收藏
页码:2026 / 2036
页数:11
相关论文
共 50 条
  • [21] Towards Robust Person Re-Identification by Defending Against Universal Attackers
    Yang, Fengxiang
    Weng, Juanjuan
    Zhong, Zhun
    Liu, Hong
    Wang, Zheng
    Luo, Zhiming
    Cao, Donglin
    Li, Shaozi
    Satoh, Shin'ichi
    Sebe, Nicu
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (04) : 5218 - 5235
  • [22] Membership Inference Attacks against MemGuard
    Niu, Ben
    Chen, Yahong
    Zhang, Likun
    Li, Fenghua
    2020 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2020,
  • [23] Privacy Against Statistical Inference
    Calmon, Flavio du Pin
    Fawaz, Nadia
    2012 50TH ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2012, : 1401 - 1408
  • [24] Witnessing Erosion of Membership Inference Defenses: Understanding Effects of Data Drift in Membership Privacy
    Na, Seung Ho
    Kim, Kwanwoo
    Shin, Seungwon
    PROCEEDINGS OF THE 26TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2023, 2023, : 250 - 263
  • [25] Parameters or Privacy: A Provable Tradeoff Between Overparameterization and Membership Inference
    Tan, Jasper
    Mason, Blake
    Javadi, Hamid
    Baraniuk, Richard G.
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [26] Effects of Differential Privacy and Data Skewness on Membership Inference Vulnerability
    Truex, Stacey
    Liu, Ling
    Gursoy, Mehmet Emre
    Wei, Wenqi
    Yu, Lei
    2019 FIRST IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2019), 2019, : 82 - 91
  • [27] Membership Inference Against DNA Methylation Databases
    Hagestedt, Inken
    Humbert, Mathias
    Berrang, Pascal
    Lehmann, Irina
    Eils, Roland
    Backes, Michael
    Zhang, Yang
    2020 5TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P 2020), 2020, : 508 - 520
  • [28] Membership Inference Attacks Against the Graph Classification
    Yang, Junze
    Li, Hongwei
    Fan, Wenshu
    Zhang, Xilin
    Hao, Meng
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 6729 - 6734
  • [29] Membership Inference Attacks against Diffusion Models
    Matsumoto, Tomoya
    Miura, Takayuki
    Yanai, Naoto
    2023 IEEE SECURITY AND PRIVACY WORKSHOPS, SPW, 2023, : 77 - 83
  • [30] Lessons Learned: Defending Against Property Inference Attacks
    Stock, Joshua
    Wettlaufer, Jens
    Demmler, Daniel
    Federrath, Hannes
    PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, SECRYPT 2023, 2023, : 312 - 323