Bilateral Dependency Optimization: Defending Against Model-inversion Attacks

Bilateral Dependency Optimization: Defending Against Model-inversion Attacks
复制标题

DOI:
10.1145/3534678.3539376
复制
发表时间:
2022-06
期刊:
Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining
影响因子:
--
通讯作者:
Xiong Peng;Feng Liu;Jingfeng Zhang;Long Lan;Junjie Ye-;Tongliang Liu;Bo Han
Xiong Peng;Feng Liu;Jingfeng Zhang;Long Lan;Junjie Ye-;Tongliang Liu;Bo Han
中科院分区:
其他
文献类型:
--
作者:
Xiong Peng;Feng Liu;Jingfeng Zhang;Long Lan;Junjie Ye-;Tongliang Liu;Bo Han

文献摘要

相似文献

模型反演(MI)攻击可以通过只使用训练好的分类器来恢复用于训练分类器的数据,从而导致训练数据的隐私泄露。为了抵御MI攻击,以前的工作利用了单边依赖优化策略,即,最小化输入之间的依赖性(即,特征)和输出(即,标签)在训练分类器期间。然而,这样的最小化过程与旨在最大化输入和输出之间的依赖性的监督损失最小化相冲突,从而导致模型对MI攻击的鲁棒性和分类任务上的模型效用之间的显式权衡。在本文中,我们的目标是最大限度地减少潜在表示和输入之间的依赖性,同时最大限度地提高潜在表示和输出之间的依赖性,称为双边依赖优化(BiDO)策略。特别地,除了深度神经网络的常用损失之外,我们还使用依赖性约束作为普遍适用的正则化器(例如,交叉熵),其可以根据不同的任务利用适当的依赖性准则来实例化。为了验证我们的策略的有效性,我们提出了两种实现的BiDO,通过使用两种不同的依赖性措施:BiDO约束协方差(BiDO-COCO)和BiDO希尔伯特施密特独立准则(BiDO-HSIC)。实验表明,BiDO实现了对各种数据集,分类器和MI攻击的最先进的防御性能,而遭受轻微的分类准确率下降相比,没有防御的训练良好的分类器,这照亮了一条新的道路,以抵御MI攻击。
Through using only a well-trained classifier, model-inversion (MI) attacks can recover the data used for training the classifier, leading to the privacy leakage of the training data. To defend against MI attacks, previous work utilizes a unilateral dependency optimization strategy, i.e., minimizing the dependency between inputs (i.e., features) and outputs (i.e., labels) during training the classifier. However, such a minimization process conflicts with minimizing the supervised loss that aims to maximize the dependency between inputs and outputs, causing an explicit trade-off between model robustness against MI attacks and model utility on classification tasks. In this paper, we aim to minimize the dependency between the latent representations and the inputs while maximizing the dependency between latent representations and the outputs, named a bilateral dependency optimization (BiDO) strategy. In particular, we use the dependency constraints as a universally applicable regularizer in addition to commonly used losses for deep neural networks (e.g., cross-entropy), which can be instantiated with appropriate dependency criteria according to different tasks. To verify the efficacy of our strategy, we propose two implementations of BiDO, by using two different dependency measures: BiDO with constrained covariance (BiDO-COCO) and BiDO with Hilbert-Schmidt Independence Criterion (BiDO-HSIC). Experiments show that BiDO achieves the state-of-the-art defense performance for a variety of datasets, classifiers, and MI attacks while suffering a minor classification-accuracy drop compared to the well-trained classifier with no defense, which lights up a novel road to defend against MI attacks.