Dissecting Distribution Inference

Dissecting Distribution Inference
复制标题

DOI:
10.1109/satml54575.2023.00019
复制
发表时间:
2022-12
期刊:
2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)
影响因子:
--
通讯作者:
Anshuman Suri;Yifu Lu;Yanjin Chen;David Evans
Anshuman Suri;Yifu Lu;Yanjin Chen;David Evans
中科院分区:
其他
文献类型:
--
作者:
Anshuman Suri;Yifu Lu;Yanjin Chen;David Evans

文献摘要

相似文献

分布推理攻击旨在推断用于训练机器学习模型的数据的统计属性。这些攻击有时威力惊人,但影响分布推理风险的因素尚未得到很好的理解,并且演示的攻击通常依赖于强大且不切实际的假设,例如即使在所谓的黑盒威胁场景中,也需要充分了解训练环境。为了提高对分布推理风险的理解,我们开发了一种新的黑盒攻击,它在大多数设置中甚至优于最著名的白盒攻击。使用这种新的攻击,我们评估分布推理风险,同时放宽有关黑盒访问下对手知识的各种假设,例如已知的模型架构和仅标签访问。最后,我们评估先前提出的防御措施的有效性并引入新的防御措施。我们发现,尽管基于噪声的防御似乎无效,但简单的重采样防御可能非常有效。
A distribution inference attack aims to infer statistical properties of data used to train machine learning models. These attacks are sometimes surprisingly potent, but the factors that impact distribution inference risk are not well understood and demonstrated attacks often rely on strong and unrealistic assumptions such as full knowledge of training environments even in supposedly black-box threat scenarios. To improve understanding of distribution inference risks, we develop a new black-box attack that even outperforms the best known white-box attack in most settings. Using this new attack, we evaluate distribution inference risk while relaxing a variety of assumptions about the adversary's knowledge under black-box access, like known model architectures and label-only access. Finally, we evaluate the effectiveness of previously proposed defenses and introduce new defenses. We find that although noise-based defenses appear to be ineffective, a simple re-sampling defense can be highly effective.