Statistical Privacy for Streaming Traffic

Statistical Privacy for Streaming Traffic
复制标题

DOI:
10.14722/ndss.2019.23210
复制
发表时间:
2019
期刊:
Proceedings 2019 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Xiaokuan Zhang;Jihun Hamm;M. Reiter;Yinqian Zhang
Xiaokuan Zhang;Jihun Hamm;M. Reiter;Yinqian Zhang
中科院分区:
其他
文献类型:
--
作者:
Xiaokuan Zhang;Jihun Hamm;M. Reiter;Yinqian Zhang

文献摘要

相似文献

- 机器学习使流量分析攻击能够从加密流量中侵犯用户的隐私。深度学习的最新进展大大加剧了这种威胁。最近展示的一个突出例子是使用卷积神经网络对视频流进行流量分析攻击。在本文中,我们探索了以前用于对抗性机器学习和差分隐私领域的技术的适应性,以减轻机器学习驱动的流媒体流量分析。我们的发现是双重的。首先,构建对抗性样本可以有效地将对手与预先确定的分类器混淆,但当对手可以通过使用替代分类器或使用对抗性样本训练分类器来适应防御时,效果就不那么有效了。其次,差分隐私保证对于这种基于推理的流量分析非常有效,同时对对手使用的机器学习类过滤器保持不可知性。我们提出了两种机制来执行加密流媒体流量的差异隐私,并评估其安全性和实用性。我们的实证实施和评估表明,所提出的统计隐私的方法是有前途的解决方案,在底层的场景。
—Machine learning empowers traffic-analysis attacks that breach users’ privacy from their encrypted traffic. Recent advances in deep learning drastically escalate such threats. One prominent example demonstrated recently is a traffic-analysis attack against video streaming by using convolutional neural networks. In this paper, we explore the adaption of techniques previously used in the domains of adversarial machine learning and differential privacy to mitigate the machine-learning-powered analysis of streaming traffic. Our findings are twofold. First, constructing adversarial samples effectively confounds an adversary with a predetermined classifier but is less effective when the adversary can adapt to the defense by using alternative classifiers or training the classifier with adversarial samples. Second, differential-privacy guarantees are very effective against such statistical-inference-based traffic analysis, while remaining agnostic to the machine learning clas-sifiers used by the adversary. We propose two mechanisms for enforcing differential privacy for encrypted streaming traffic, and evaluate their security and utility. Our empirical implementation and evaluation suggest that the proposed statistical privacy approaches are promising solutions in the underlying scenarios.