Black-Box Based Limited Query Membership Inference Attack

被引:4
|
作者
Zhang, Yu [1 ]
Zhou, Huaping [1 ]
Wang, Pengyan [1 ]
Yang, Gaoming [1 ]
机构
[1] Anhui Univ Sci & Technol, Sch Comp Sci & Engn, Huainan 232001, Peoples R China
关键词
Data models; Training; Adaptation models; Training data; Predictive models; Generative adversarial networks; Machine learning; Membership inference attack; generative adversarial network; black-box attack; information leak;
D O I
10.1109/ACCESS.2022.3175824
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Conventional membership inference attacks usually require a large number of queries of the target model when training shadow models, and this task becomes extremely difficult when the number of queries is limited. Aiming at the problem of insufficient training data for shadow models due to the limited number of queries, we propose a membership inference attack method based on generative adversarial networks (GAN). First, we use generative adversarial networks to augment the samples obtained by a small number of queries to expand the training data of the model; Secondly, we use the improved CNN to obtain shadow models that have a higher degree of fitting on different target model structures; Finally, we evaluate the accuracy of the proposed algorithm on XgBoost, Logistic, and neural network models using public datasets MNIST and CIFAR10 in a black-box setting, and the results show that our model has an average attack accuracy of 62% and 83%, respectively. It can be seen that, compared with the existing research methods, our model can obtain better attack effects under the condition of significantly reducing the number of queries, which shows the feasibility of our proposed method in membership inference attacks.
引用
收藏
页码:55459 / 55468
页数:10
相关论文
共 50 条
  • [1] GANMIA: GAN-based Black-box Membership Inference Attack
    Bai, Yang
    Chen, Degang
    Chen, Ting
    Fan, Mingyu
    [J]. IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2021), 2021,
  • [2] Black-box membership inference attacks based on shadow model
    Han Zhen
    Zhou Wen'an
    Han Xiaoxuan
    Wu Jie
    [J]. The Journal of China Universities of Posts and Telecommunications., 2024, 31 (04) - 16
  • [3] Improved black-box attack based on query and perturbation distribution
    Zhao, Weiwei
    Zeng, Zhigang
    [J]. 2021 13TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTATIONAL INTELLIGENCE (ICACI), 2021, : 117 - 125
  • [4] A low-query black-box adversarial attack based on transferability
    Ding, Kangyi
    Liu, Xiaolei
    Niu, Weina
    Hu, Teng
    Wang, Yanping
    Zhang, Xiaosong
    [J]. KNOWLEDGE-BASED SYSTEMS, 2021, 226
  • [5] Query-Efficient Decision-Based Black-Box Patch Attack
    Chen, Zhaoyu
    Li, Bo
    Wu, Shuang
    Ding, Shouhong
    Zhang, Wenqiang
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5522 - 5536
  • [6] Query-Efficient Black-Box Attack by Active Learning
    Li, Pengcheng
    Yi, Jinfeng
    Zhang, Lijun
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2018, : 1200 - 1205
  • [7] Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object Detection
    Liang, Siyuan
    Wu, Baoyuan
    Fan, Yanbo
    Wei, Xingxing
    Cao, Xiaochun
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 7677 - 7687
  • [8] Query-based black-box attack against medical image segmentation model
    Li, Siyuan
    Huang, Guangji
    Xu, Xing
    Lu, Huimin
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 133 : 331 - 337
  • [9] Query efficient black-box adversarial attack on deep neural networks
    Bai, Yang
    Wang, Yisen
    Zeng, Yuyuan
    Jiang, Yong
    Xia, Shu-Tao
    [J]. PATTERN RECOGNITION, 2023, 133
  • [10] Query-Efficient Target-Agnostic Black-Box Attack
    Moraffah, Raha
    Liu, Huan
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2022, : 368 - 377