Chameleon: Increasing Label-Only Membership Leakage with Adaptive Poisoning

Chameleon: Increasing Label-Only Membership Leakage with Adaptive Poisoning
复制标题

DOI:
10.48550/arxiv.2310.03838
复制
发表时间:
2023-10
期刊:
ArXiv
影响因子:
--
通讯作者:
Harsh Chaudhari;Giorgio Severi;Alina Oprea;Jonathan R. Ullman
Harsh Chaudhari;Giorgio Severi;Alina Oprea;Jonathan R. Ullman
中科院分区:
其他
文献类型:
--
作者:
Harsh Chaudhari;Giorgio Severi;Alina Oprea;Jonathan R. Ullman

文献摘要

相似文献

机器学习(ML)在许多关键应用中的集成为提供数据集进行模型训练的个人带来了一系列隐私问题。其中一个隐私风险是成员资格推断(MI),其中攻击者试图确定特定数据样本是否包含在模型的训练数据集中。当前最先进的MI攻击利用对模型的预测置信度分数的访问来成功地执行成员推断,并采用数据中毒来进一步增强其有效性。在这项工作中,我们专注于较少探索和更现实的标签设置,其中模型仅提供查询样本上的预测标签。我们发现,现有的标签只有MI攻击是无效的推断成员在低误报率(FPR)制度。为了应对这一挑战,我们提出了一种新的攻击变色龙,利用一种新的自适应数据中毒策略和一种有效的查询选择方法,以实现更准确的成员推理比现有的标签,特别是在低FPRs的攻击。
The integration of machine learning (ML) in numerous critical applications introduces a range of privacy concerns for individuals who provide their datasets for model training. One such privacy risk is Membership Inference (MI), in which an attacker seeks to determine whether a particular data sample was included in the training dataset of a model. Current state-of-the-art MI attacks capitalize on access to the model's predicted confidence scores to successfully perform membership inference, and employ data poisoning to further enhance their effectiveness. In this work, we focus on the less explored and more realistic label-only setting, where the model provides only the predicted label on a queried sample. We show that existing label-only MI attacks are ineffective at inferring membership in the low False Positive Rate (FPR) regime. To address this challenge, we propose a new attack Chameleon that leverages a novel adaptive data poisoning strategy and an efficient query selection method to achieve significantly more accurate membership inference than existing label-only attacks, especially at low FPRs.