paper-with-me

홈 › Papers

Machine Learning with Membership Privacy using Adversarial Regularization

2018-07-16 · Milad Nasr, Reza Shokri, Amir Houmansadr

Machine learning models leak information about the datasets on which they are trained. An adversary can build an algorithm to trace the individual members of a model's training dataset. As a fundamental inference attack, he aims to distinguish between data points that were part of the model's training set and any other data points from the same distribution. This is known as the tracing (and also membership inference) attack. In this paper, we focus on such attacks against black-box models, where the adversary can only observe the output of the model, but not its parameters. This is the current setting of machine learning as a service in the Internet. We introduce a privacy mechanism to train machine learning models that provably achieve membership privacy: the model's predictions on its training data are indistinguishable from its predictions on other data points from the same distribution. We design a strategic mechanism where the privacy mechanism anticipates the membership inference attacks. The objective is to train a model such that not only does it have the minimum prediction error (high utility), but also it is the most robust model against its corresponding strongest inference attack (high privacy). We formalize this as a min-max game optimization problem, and design an adversarial training algorithm that minimizes the classification loss of the model as well as the maximum gain of the membership inference attack against it. This strategy, which guarantees membership privacy (as prediction indistinguishability), acts also as a strong regularizer and significantly generalizes the model. We evaluate our privacy mechanism on deep neural networks using different benchmark datasets. We show that our min-max strategy can mitigate the risk of membership inference attacks (close to the random guess) with a negligible cost in terms of the classification error.

📄 PDF Abstract BibTeX arXiv:1807.05852

Code (1)

hyhmia/BlindMI tf

Tasks

BIG-bench Machine LearningGeneral ClassificationInference AttackMembership Inference Attack

Similar Papers 제목 키워드 기반

Membership Privacy for Machine Learning Models Through Knowledge Transfer

2019-06-15 · Virat Shejwalkar, Amir Houmansadr

Large capacity machine learning (ML) models are prone to membership inference attacks (MIAs), which aim to infer whether the target sample is a member of the target model's training dataset. The serious privacy concerns …

BIG-bench Machine LearningGeneral ClassificationInference AttackKnowledge Distillation+2

Effectiveness of L2 Regularization in Privacy-Preserving Machine Learning

2024-12-02 · Nikolaos Chandrinos, Iliana Loi, Panagiotis Zachos, Ioannis Symeonidis 외

Artificial intelligence, machine learning, and deep learning as a service have become the status quo for many industries, leading to the widespread deployment of models that handle sensitive data. Well-performing models,…

Inference AttackL2 RegularizationMembership Inference AttackPrivacy Preserving

Label-Only Membership Inference Attacks

2020-07-28 · Christopher A. Choquette-Choo, Florian Tramer, Nicholas Carlini, Nicolas Papernot

Membership inference attacks are one of the simplest forms of privacy leakage for machine learning models: given a data point and model, determine whether the point was used to train the model. Existing membership infere…

L2 Regularization

On the Effectiveness of Regularization Against Membership Inference Attacks

2020-06-09 · Yigitcan Kaya, Sanghyun Hong, Tudor Dumitras

Deep learning models often raise privacy concerns as they leak information about their training data. This enables an adversary to determine whether a data point was in a model's training set by conducting a membership i…

image-classificationImage ClassificationInference AttackMembership Inference Attack

Effects of Differential Privacy and Data Skewness on Membership Inference Vulnerability

2019-11-21 · Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Wenqi Wei 외

Membership inference attacks seek to infer the membership of individual training instances of a privately trained model. This paper presents a membership privacy analysis and evaluation system, called MPLens, with three …

Inference AttackMembership Inference Attack