Membership Inference Attacks and Defenses in Neural Network Pruning

Membership Inference Attacks and Defenses in Neural Network Pruning
复制标题

DOI:
--
复制
发表时间:
2022-02
期刊:
--
影响因子:
--
通讯作者:
Xiaoyong Yuan;Lan Zhang
Xiaoyong Yuan;Lan Zhang
中科院分区:
其他
文献类型:
--
作者:
Xiaoyong Yuan;Lan Zhang

文献摘要

被引文献

相似文献

神经网络剪枝一直是一项关键技术,用于降低在资源受限设备上使用深度神经网络的计算和内存需求。现有的大多数研究主要集中在通过策略性地移除不重要的参数并重新训练剪枝后的模型来平衡剪枝神经网络的稀疏性和准确性。由于记忆增强,这种对训练样本复用的做法带来了严重的隐私风险,然而这一点尚未得到研究。在本文中,我们首次对神经网络剪枝中的隐私风险进行了分析。具体而言,我们研究了神经网络剪枝对训练数据隐私的影响,即成员推断攻击。我们首先探讨了神经网络剪枝对预测差异的影响,其中剪枝过程对成员和非成员的剪枝模型行为产生不成比例的影响。同时,这种差异的影响甚至在不同类别之间以细粒度的方式有所不同。受这种差异的启发,我们针对剪枝后的神经网络提出了一种自注意力成员推断攻击。我们进行了大量实验,以严格评估不同剪枝方法、稀疏程度和攻击者知识对隐私的影响。与现有的八种成员推断攻击相比,所提出的攻击在剪枝模型上表现出更高的攻击性能。此外,我们提出了一种新的防御机制,通过基于KL散度距离减轻预测差异来保护剪枝过程,实验证明其有效性,能够在保持剪枝模型的稀疏性和准确性的同时有效降低隐私风险。
Neural network pruning has been an essential technique to reduce the computation and memory requirements for using deep neural networks for resource-constrained devices. Most existing research focuses primarily on balancing the sparsity and accuracy of a pruned neural network by strategically removing insignificant parameters and retraining the pruned model. Such efforts on reusing training samples pose serious privacy risks due to increased memorization, which, however, has not been investigated yet. In this paper, we conduct the first analysis of privacy risks in neural network pruning. Specifically, we investigate the impacts of neural network pruning on training data privacy, i.e., membership inference attacks. We first explore the impact of neural network pruning on prediction divergence, where the pruning process disproportionately affects the pruned model's behavior for members and non-members. Meanwhile, the influence of divergence even varies among different classes in a fine-grained manner. Enlighten by such divergence, we proposed a self-attention membership inference attack against the pruned neural networks. Extensive experiments are conducted to rigorously evaluate the privacy impacts of different pruning approaches, sparsity levels, and adversary knowledge. The proposed attack shows the higher attack performance on the pruned models when compared with eight existing membership inference attacks. In addition, we propose a new defense mechanism to protect the pruning process by mitigating the prediction divergence based on KL-divergence distance, whose effectiveness has been experimentally demonstrated to effectively mitigate the privacy risks while maintaining the sparsity and accuracy of the pruned models.