Enhanced Membership Inference Attacks against Machine Learning Models

Enhanced Membership Inference Attacks against Machine Learning Models
复制标题

针对机器学习模型的增强型成员推理攻击

DOI:
10.1145/3548606.3560675
复制
发表时间:
2021
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
R. Shokri
R. Shokri
中科院分区:
--
文献类型:
--
作者:
Jiayuan Ye;Aadyaa Maddi;S. K. Murakonda;R. Shokri

文献摘要

参考文献

被引文献

相似文献

机器学习算法会泄露多少训练数据,为什么?成员推断攻击被用作审计工具来量化这种泄漏。在本文中,我们提出了一个comprehensivehypothesis testing框架,使我们不仅能够以一致的方式正式表达先前的工作,而且还可以设计新的成员推理攻击,使用参考模型来实现任何(假阳性率)错误的显着更高的功率(真阳性率)。更重要的是,我们解释了为什么不同的攻击表现不同。我们提出了一个模板不可分割的游戏,并提供了一个解释的攻击成功率在不同的游戏实例。我们讨论了各种不确定性的攻击者所产生的制定的问题,并显示我们的方法试图尽量减少攻击的不确定性的一位秘密的训练集中的数据点的存在或不存在。我们对所有类型的攻击进行了差异分析,解释了它们之间的差距,并展示了导致数据点容易受到攻击的原因(原因因记忆粒度的不同而异,从过拟合到条件记忆)。我们的审计框架是作为隐私计量软件工具的一部分公开访问的。
How much does a machine learning algorithm leak about its training data, and why? Membership inference attacks are used as an auditing tool to quantify this leakage. In this paper, we present a comprehensivehypothesis testing framework that enables us not only to formally express the prior work in a consistent way, but also to design new membership inference attacks that use reference models to achieve a significantly higher power (true positive rate) for any (false positive rate) error. More importantly, we explainwhy different attacks perform differently. We present a template for indistinguishability games, and provide an interpretation of attack success rate across different instances of the game. We discuss various uncertainties of attackers that arise from the formulation of the problem, and show how our approach tries to minimize the attack uncertainty to the one bit secret about the presence or absence of a data point in the training set. We perform adifferential analysis between all types of attacks, explain the gap between them, and show what causes data points to be vulnerable to an attack (as the reasons vary due to different granularities of memorization, from overfitting to conditional memorization). Our auditing framework is openly accessible as part of thePrivacy Meter software tool.
DOI: --
发表时间: 2020-06
期刊: ArXiv
影响因子: --
作者:
Matthew Jagielski;Jonathan Ullman;Alina Oprea
通讯作者: Matthew Jagielski;Jonathan Ullman;Alina Oprea
DOI: 10.1145/3133956.3134077
发表时间: 2017-09
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Congzheng Song;Thomas Ristenpart;Vitaly Shmatikov
通讯作者: Congzheng Song;Thomas Ristenpart;Vitaly Shmatikov
DOI: 10.1145/3292500.3330885
发表时间: 2018-11
期刊: Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining
影响因子: --
作者:
Congzheng Song;Vitaly Shmatikov
通讯作者: Congzheng Song;Vitaly Shmatikov