Understanding Disparate Effects of Membership Inference Attacks and their Countermeasures

Understanding Disparate Effects of Membership Inference Attacks and their Countermeasures
复制标题

了解成员推理攻击的不同影响及其对策

DOI:
10.1145/3488932.3501279
复制
发表时间:
2022
期刊:
Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Wang, Wendy Hui
Wang, Wendy Hui
中科院分区:
--
文献类型:
--
作者:
Zhong, Da;Sun, Haipei;Xu, Jun;Gong, Neil;Wang, Wendy Hui

文献摘要

参考文献

被引文献

相似文献

当机器学习算法应用于敏感数据时,可能会对隐私构成严重威胁。越来越多的先前工作已经证明,成员推断攻击(MIA)可以向攻击者泄露训练数据中是否存在特定的私有数据样本。然而,大多数现有的关于MIA的研究都集中在整个人群的聚合隐私泄露上,而将隐私泄露留给不同的人口统计学亚组(例如,女性和男性)在种群中基本上未被探索。这提出了两个重要问题:(1)隐私不公平(即,如果一些子组比其它子组更易受MIA的影响);以及(2)防御不公平(即,在本文中,我们研究了隐私不公平性和防御公平性,提出了一种新的隐私泄漏差异(PLD)的概念,它量化了不同子组的机器学习模型对MIA的不同隐私泄漏。在隐私不公平方面,我们在真实世界数据集上对PLD的实证分析表明,隐私不公平是存在的。少数群体(即,较少代表的子组)往往具有较高的隐私泄露。我们通过模型记忆的透镜来分析子组大小和子组数据分布对PLD的影响。在防御不公平性方面,我们的实证评估显示,三个国家的最先进的防御,即差分隐私,L2正则化,辍学,对MIA的不公平性的存在。然而,国防不公平减轻隐私不公平,因为少数群体比其他人得到更强的保护。我们分析了这三种防御机制是如何共同影响子组数据分布,从而导致防御不公平的。
Machine learning algorithms, when applied to sensitive data, can pose severe threats to privacy. A growing body of prior work has demonstrated that membership inference attack (MIA) can disclose whether specific private data samples are present in the training data to an attacker. However, most existing studies on MIA focus on aggregated privacy leakage for an entire population, while leaving privacy leakage across different demographic subgroups (e.g., females and males) in the population largely unexplored. This raises two important issues: (1) privacy unfairness (i.e., if some subgroups are more vulnerable to MIAs than the others); and (2) defense unfairness (i.e., if the defense mechanisms provide more protection to some particular subgroups than the others).In this paper, we investigate both privacy unfairness and defense fairness.We formalize a new notation of privacy-leakage disparity (PLD), which quantifies the disparate privacy leakage of machine learning models to MIA across different subgroups. In terms of privacy unfairness, our empirical analysis of PLD on real-world datasets shows that privacy unfairness exists. The minority subgroups (i.e., the less represented subgroups) tend to have higher privacy leakage. We analyze how subgroup size and subgroup data distribution impact PLD through the lens of model memorization. In terms of defense unfairness, our empirical evaluation shows the existence of unfairness of three state-of-the-art defenses, namely differential privacy, L2-regularizer, and Dropout, against MIA. However, defense unfairness mitigates privacy unfairness as the minority subgroups receive stronger protection than the others. We analyze how the three defense mechanisms affect subgroup data distribution disparately and thus leads to defense unfairness.
DOI: --
发表时间: 2020-06
期刊: ArXiv
影响因子: --
作者:
Matthew Jagielski;Jonathan Ullman;Alina Oprea
通讯作者: Matthew Jagielski;Jonathan Ullman;Alina Oprea
DOI: 10.1609/aaai.v35i11.17193
发表时间: 2020-09
期刊: ArXiv
影响因子: --
作者:
Cuong Tran;Ferdinando Fioretto;Pascal Van Hentenryck
通讯作者: Cuong Tran;Ferdinando Fioretto;Pascal Van Hentenryck
使用隐私攻击策略的反歧视分析
DOI: 10.1007/978-3-662-44851-9_44
发表时间: 2014
期刊: AJR. American journal of roentgenology
影响因子: --
作者:
S. Ruggieri;S. Hajian;F. Kamiran;Xiangliang Zhang
通讯作者: Xiangliang Zhang
所有人的隐私:确保公平公正的隐私保护
DOI: --
发表时间: 2018
期刊: Accountability and Transparency
影响因子: --
作者:
Ekstrand, Michael D.;Joshaghani, Rezvan;Mehrpouyan, Hoda
通讯作者: Mehrpouyan, Hoda
不利影响和测试验证:有效且合理的就业测试的从业者指南
DOI: --
发表时间: 2005
期刊:
影响因子: --
作者:
Dan A. Biddle
通讯作者: Dan A. Biddle