Against Membership Inference Attack: Pruning is All You Need

Against Membership Inference Attack: Pruning is All You Need
复制标题

DOI:
10.24963/ijcai.2021/432
复制
发表时间:
2020-08
期刊:
--
影响因子:
--
通讯作者:
Yijue Wang;Chenghong Wang;Zigeng Wang;Shangli Zhou;Hang Liu;J. Bi;Caiwen Ding;S. Rajasekaran
Yijue Wang;Chenghong Wang;Zigeng Wang;Shangli Zhou;Hang Liu;J. Bi;Caiwen Ding;S. Rajasekaran
中科院分区:
其他
文献类型:
--
作者:
Yijue Wang;Chenghong Wang;Zigeng Wang;Shangli Zhou;Hang Liu;J. Bi;Caiwen Ding;S. Rajasekaran

文献摘要

相似文献

大的模型大小、高计算操作和对成员推理攻击(MIA)的脆弱性阻碍了深度学习或深度神经网络(DNN)的普及,特别是在移动的设备上。为了应对这一挑战,我们设想权重修剪技术将有助于DNN对抗MIA,同时减少模型存储和计算操作。在这项工作中,我们提出了一个修剪算法,我们表明,该算法可以找到一个子网络,可以防止隐私泄漏从MIA,并实现竞争的准确性与原来的DNN。我们还验证了我们的理论见解与实验。实验结果表明,使用模型压缩的攻击准确率高达13.6%,比基线和Min-Max游戏的准确率低10%。
The large model size, high computational operations, and vulnerability against membership inference attack (MIA) have impeded deep learning or deep neural networks (DNNs) popularity, especially on mobile devices. To address the challenge, we envision that the weight pruning technique will help DNNs against MIA while reducing model storage and computational operation. In this work, we propose a pruning algorithm, and we show that the proposed algorithm can find a subnetwork that can prevent privacy leakage from MIA and achieves competitive accuracy with the original DNNs. We also verify our theoretical insights with experiments. Our experimental results illustrate that the attack accuracy using model compression is up to 13.6% and 10% lower than that of the baseline and Min-Max game, accordingly.