paper-with-me

Papers

Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning

2018-12-03 · Milad Nasr, Reza Shokri, Amir Houmansadr

Deep neural networks are susceptible to various inference attacks as they remember information about their training data. We design white-box inference attacks to perform a comprehensive privacy analysis of deep learning models. We measure the privacy leakage through parameters of fully trained models as well as the parameter updates of models during training. We design inference algorithms for both centralized and federated learning, with respect to passive and active inference attackers, and assuming different adversary prior knowledge. We evaluate our novel white-box membership inference attacks against deep learning algorithms to trace their training data records. We show that a straightforward extension of the known black-box attacks to the white-box setting (through analyzing the outputs of activation functions) is ineffective. We therefore design new algorithms tailored to the white-box setting by exploiting the privacy vulnerabilities of the stochastic gradient descent algorithm, which is the algorithm used to train deep neural networks. We investigate the reasons why deep learning models may leak information about their training data. We then show that even well-generalized models are significantly susceptible to white-box membership inference attacks, by analyzing state-of-the-art pre-trained and publicly available models for the CIFAR dataset. We also show how adversarial participants, in the federated learning setting, can successfully run active membership inference attacks against other participants, even when the global model achieves high prediction accuracies.

📄 PDF Abstract BibTeX arXiv:1812.00910

Code (4)

privacytrustlab/ml_privacy_meter 공식 구현 tf
ganeshdg95/leveraging-adversarial-examples-to-quantify-membership-information-leakage pytorch
giladcohen/sif_mi_attack pytorch
jefffffffu/dpsur pytorch

Tasks

Deep LearningFederated Learning

Similar Papers 제목 키워드 기반

Privacy Against Agnostic Inference Attacks in Vertical Federated Learning

2023-02-10 · Morteza Varasteh

A novel form of inference attack in vertical federated learning (VFL) is proposed, where two parties collaborate in training a machine learning (ML) model. Logistic regression is considered for the VFL model. One party, …

Federated LearningInference AttackPrivacy PreservingVertical Federated Learning

Privacy-Preserving by Design: Indoor Positioning System Using Wi-Fi Passive TDOA

2023-06-03 · Mohamed Mohsen, Hamada Rizk, Moustafa Youssef

Indoor localization systems have become increasingly important in a wide range of applications, including industry, security, logistics, and emergency services. However, the growing demand for accurate localization has h…

Indoor LocalizationPrivacy Preserving

On the Detectability of Active Gradient Inversion Attacks in Federated Learning

2025-11-13 · Vincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella 외 arxiv

One of the key advantages of Federated Learning (FL) is its ability to collaboratively train a Machine Learning (ML) model while keeping clients' data on-site. However, this can create a false sense of security. Despite …

Federated Learning

Privacy Against Inference Attacks in Vertical Federated Learning

2022-07-24 · Borzoo Rassouli, Morteza Varasteh, Deniz Gunduz

Vertical federated learning is considered, where an active party, having access to true class labels, wishes to build a classification model by utilizing more features from a passive party, which has no access to the lab…

Federated LearningInference AttackPrivacy PreservingVertical Federated Learning

Determined by User Needs: A Salient Object Detection Rationale Beyond Conventional Visual Stimuli

2026-04-04 · Chenglizhao Chen, Shujian Zhang, Luming Li, Wenfeng Song 외 arxiv

Existing \textbf{s}alient \textbf{o}bject \textbf{d}etection (SOD) methods adopt a \textbf{passive} visual stimulus-based rationale--objects with the strongest visual stimuli are perceived as the user's primary focus (i.…

Salient Object Detection