User-Level Membership Inference Attack against Metric Embedding Learning

User-Level Membership Inference Attack against Metric Embedding Learning
复制标题

DOI:
10.48550/arxiv.2203.02077
复制
发表时间:
2022-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Guoyao Li;Shahbaz Rezaei;Xin Liu
Guoyao Li;Shahbaz Rezaei;Xin Liu
中科院分区:
其他
文献类型:
--
作者:
Guoyao Li;Shahbaz Rezaei;Xin Liu

文献摘要

相似文献

隶属度推理(MI)确定样本是否为受害者模型训练集的一部分。MI攻击的最新发展集中在记录级成员关系推理上,这限制了它们在许多现实世界场景中的应用。例如,在人员重新识别任务中,攻击者(或调查员)感兴趣的是确定用户的图像在训练期间是否被使用。然而,攻击者可能无法访问准确的训练图像。在本文中,我们开发了一个用户级别的MI攻击,目标是在攻击者没有确切的训练样本的情况下,发现目标用户的样本在训练过程中是否被使用过。由于度量嵌入学习在人的重新识别中的优势,我们将重点放在度量嵌入学习上,在这种情况下,用户级MI攻击更敏感。我们在几个数据集上进行了广泛的评估,结果表明,我们的方法在用户级MI任务上达到了很高的准确率。
Membership inference (MI) determines if a sample was part of a victim model training set. Recent development of MI attacks focus on record-level membership inference which limits their application in many real-world scenarios. For example, in the person re-identification task, the attacker (or investigator) is interested in determining if a user's images have been used during training or not. However, the exact training images might not be accessible to the attacker. In this paper, we develop a user-level MI attack where the goal is to find if any sample from the target user has been used during training even when no exact training sample is available to the attacker. We focus on metric embedding learning due to its dominance in person re-identification, where user-level MI attack is more sensible. We conduct an extensive evaluation on several datasets and show that our approach achieves high accuracy on user-level MI task.