NeuGuard: Lightweight Neuron-Guided Defense against Membership Inference Attacks

NeuGuard: Lightweight Neuron-Guided Defense against Membership Inference Attacks
复制标题

DOI:
10.1145/3564625.3567986
复制
发表时间:
2022-06
期刊:
Proceedings of the 38th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Nuo Xu;Binghui Wang;Ran Ran-Ran;Wujie Wen;P. Venkitasubramaniam
Nuo Xu;Binghui Wang;Ran Ran-Ran;Wujie Wen;P. Venkitasubramaniam
中科院分区:
其他
文献类型:
--
作者:
Nuo Xu;Binghui Wang;Ran Ran-Ran;Wujie Wen;P. Venkitasubramaniam

文献摘要

被引文献

相似文献

针对机器学习模型的成员推理攻击(mia)会给模型训练中使用的训练数据集带来严重的隐私风险。针对mia的最先进防御通常存在较差的隐私效用平衡和防御通用性,以及较高的训练或推理开销。为了克服这些限制,在本文中,我们提出了一种新颖,轻量级和有效的神经元制导防御方法,称为NeuGuard。不同于现有的在训练中对所有模型参数进行正则化,或者在实时推理中对每个输入的噪声模型输出进行正则化的解决方案,NeuGuard旨在通过细粒度的神经元正则化,明智地引导训练集和测试集的模型输出具有接近的分布。也就是说,通过使用我们开发的类明智的方差最小化和层明智的平衡输出控制,同时限制每层中输出神经元和内部神经元的激活。我们对NeuGuard进行了评估,并将其与针对两种基于神经网络的MIA、五种最强大的基于度量的MIA(包括新提出的基于三个基准数据集的纯标签MIA)的最先进防御进行了比较。广泛的实验结果表明,NeuGuard通过提供更好的效用-隐私权衡、通用性和开销,胜过最先进的防御。我们的代码可以在https://github.com/nux219/NeuGuard上公开获得。
Membership inference attacks (MIAs) against machine learning models lead to serious privacy risks for the training dataset used in the model training. The state-of-the-art defenses against MIAs often suffer from poor privacy-utility balance and defense generality, as well as high training or inference overhead. To overcome these limitations, in this paper, we propose a novel, lightweight and effective Neuron-Guided Defense method named NeuGuard against MIAs. Unlike existing solutions which either regularize all model parameters in training or noise model output per input in real-time inference, NeuGuard aims to wisely guide the model output of training set and testing set to have close distributions through a fine-grained neuron regularization. That is, restricting the activation of output neurons and inner neurons in each layer simultaneously by using our developed class-wise variance minimization and layer-wise balanced output control. We evaluate NeuGuard and compare it with state-of-the-art defenses against two neural network based MIAs, five strongest metric based MIAs including the newly proposed label-only MIA on three benchmark datasets. Extensive experimental results show that NeuGuard outperforms the state-of-the-art defenses by offering much improved utility-privacy trade-off, generality, and overhead. Our code is publicly available at https://github.com/nux219/NeuGuard.