Practical Blind Membership Inference Attack via Differential Comparisons

Practical Blind Membership Inference Attack via Differential Comparisons
复制标题

DOI:
10.14722/ndss.2021.24293
复制
发表时间:
2021-01
期刊:
ArXiv
影响因子:
--
通讯作者:
Bo Hui;Yuchen Yang;Haolin Yuan;P. Burlina;N. Gong;Yinzhi Cao
Bo Hui;Yuchen Yang;Haolin Yuan;P. Burlina;N. Gong;Yinzhi Cao
中科院分区:
其他
文献类型:
--
作者:
Bo Hui;Yuchen Yang;Haolin Yuan;P. Burlina;N. Gong;Yinzhi Cao

文献摘要

被引文献

相似文献

成员推理(MI)攻击通过推断给定的数据样本是否已被用于训练目标学习模型(例如深度神经网络)来影响用户隐私。文献中有两种类型的MI攻击,即使用影子模型的和不使用影子模型的。前者的成功在很大程度上取决于影子模型的质量,即影子模型和目标模型之间的可迁移性;后者在仅对目标模型有黑盒探测访问权限的情况下,由于带有真实成员信息标注的合格样本数量不足,与使用影子模型的MI攻击相比,无法对未知情况进行有效推理。在本文中,我们提出了一种MI攻击,称为BlindMI,它通过一种新颖的方法(称为差分比较)探测目标模型并提取成员语义。其高层次的思路是,BlindMI首先通过将现有样本转换为新样本生成一个非成员数据集,然后以迭代的方式将样本从目标数据集差异地移动到生成的非成员集合中。如果一个样本的差异移动增加了集合距离,BlindMI就将该样本视为非成员,反之亦然。通过与最先进的MI攻击算法进行比较对BlindMI进行了评估。我们的评估表明,在对手不知道目标模型的架构和目标数据集的真实标签的盲设置下,在一些数据集(如Purchase - 50和Birds - 200)上,与最先进的技术相比,BlindMI将F1分数提高了近20%。我们还表明BlindMI可以突破最先进的防御。
Membership inference (MI) attacks affect user privacy by inferring whether given data samples have been used to train a target learning model, e.g., a deep neural network. There are two types of MI attacks in the literature, i.e., these with and without shadow models. The success of the former heavily depends on the quality of the shadow model, i.e., the transferability between the shadow and the target; the latter, given only blackbox probing access to the target model, cannot make an effective inference of unknowns, compared with MI attacks using shadow models, due to the insufficient number of qualified samples labeled with ground truth membership information. In this paper, we propose an MI attack, called BlindMI, which probes the target model and extracts membership semantics via a novel approach, called differential comparison. The high-level idea is that BlindMI first generates a dataset with nonmembers via transforming existing samples into new samples, and then differentially moves samples from a target dataset to the generated, non-member set in an iterative manner. If the differential move of a sample increases the set distance, BlindMI considers the sample as non-member and vice versa. BlindMI was evaluated by comparing it with state-of-the-art MI attack algorithms. Our evaluation shows that BlindMI improves F1-score by nearly 20% when compared to state-of-the-art on some datasets, such as Purchase-50 and Birds-200, in the blind setting where the adversary does not know the target model's architecture and the target dataset's ground truth labels. We also show that BlindMI can defeat state-of-the-art defenses.