Privacy-preserving Naive Bayes classifiers secure against the substitution-then-comparison attack

Privacy-preserving Naive Bayes classifiers secure against the substitution-then-comparison attack
复制标题

DOI:
10.1016/j.ins.2018.02.058
复制
发表时间:
2018-05-01
影响因子:
8.1
通讯作者:
Li, Jin
Li, Jin
中科院分区:
计算机科学1区
文献类型:
--
作者:
Gao, Chong-zhi;Cheng, Qiong;Li, Jin

文献摘要

被引文献

相似文献

朴素贝叶斯(NB)是一种简单但高度实用的分类器,具有广泛的应用,包括垃圾邮件过滤器、癌症诊断和人脸识别,仅举几个例子。考虑用户从NB分类器服务器请求分类服务的情况,用户和服务器都不想向对方透露他们的私有数据。本文的重点是构造一个隐私保护的NB分类器,该分类器能够抵抗一种易于执行但难以检测的攻击,我们称之为替换-然后比较(STC)攻击。在不采用计算开销较大的全同态加密的情况下,提出了一种避免STC攻击下的信息泄漏的方案。我们的关键技术涉及到“双盲”技术的使用,我们展示了如何将其与加性同态加密和不经意传输相结合来隐藏双方的隐私。此外,完成的评估表明,该结构具有很高的实用性--大多数计算都处于服务器的离线阶段,在线计算和通信的开销对双方来说都很小。(C)2018 Elsevier Inc.保留所有权利。
Naive Bayes (NB) is a simple but highly practical classifier, with a wide range of applications including spam filters, cancer diagnosis and face recognition, to name a few examples only. Consider a situation where a user requests a classification service from a NB classifier server, both the user and the server do not want to reveal their private data to each other. This paper focuses on constructing a privacy-preserving NB classifier that is resistant to an easy-to-perform, but difficult-to-detect attack, which we call the substitution-then comparison (STC) attack. Without resorting to fully homomorphic encryptions, which has a high computational overhead, we propose a scheme which avoids information leakage under the STC attack. Our key technique involves the use of a "double-blinding" technique, and we show how to combine it with additively homomorphic encryptions and oblivious transfer to hide both parties' privacy. Furthermore, a completed evaluation shows that the construction is highly practical - most of the computations are in the server's offline phase, and the overhead of online computation and communication is small for both parties. (C) 2018 Elsevier Inc. All rights reserved.