paper-with-me

홈 › Papers

On the Evaluation of User Privacy in Deep Neural Networks using Timing Side Channel

2022-08-01 · Shubhi Shukla, Manaar Alam, Sarani Bhattacharya, Debdeep Mukhopadhyay, Pabitra Mitra

Recent Deep Learning (DL) advancements in solving complex real-world tasks have led to its widespread adoption in practical applications. However, this opportunity comes with significant underlying risks, as many of these models rely on privacy-sensitive data for training in a variety of applications, making them an overly-exposed threat surface for privacy violations. Furthermore, the widespread use of cloud-based Machine-Learning-as-a-Service (MLaaS) for its robust infrastructure support has broadened the threat surface to include a variety of remote side-channel attacks. In this paper, we first identify and report a novel data-dependent timing side-channel leakage (termed Class Leakage) in DL implementations originating from non-constant time branching operation in a widely used DL framework PyTorch. We further demonstrate a practical inference-time attack where an adversary with user privilege and hard-label black-box access to an MLaaS can exploit Class Leakage to compromise the privacy of MLaaS users. DL models are vulnerable to Membership Inference Attack (MIA), where an adversary's objective is to deduce whether any particular data has been used while training the model. In this paper, as a separate case study, we demonstrate that a DL model secured with differential privacy (a popular countermeasure against MIA) is still vulnerable to MIA against an adversary exploiting Class Leakage. We develop an easy-to-implement countermeasure by making a constant-time branching operation that alleviates the Class Leakage and also aids in mitigating MIA. We have chosen two standard benchmarking image classification datasets, CIFAR-10 and CIFAR-100 to train five state-of-the-art pre-trained DL models, over two different computing environments having Intel Xeon and Intel i7 processors to validate our approach.

📄 PDF Abstract BibTeX arXiv:2208.01113

Code (0)

등록된 구현이 없습니다.

Tasks

Benchmarkingimage-classificationImage ClassificationInference AttackMembership Inference Attack

Similar Papers 제목 키워드 기반

Auditing Prompt Caching in Language Model APIs

2025-02-11 · Chenchen Gu, Xiang Lisa Li, Rohith Kuditipudi, Percy Liang 외

Prompt caching in large language models (LLMs) results in data-dependent timing variations: cached prompts are processed faster than non-cached prompts. These timing differences introduce the risk of side-channel timing …

DecoderLanguage ModelingLanguage Modellingmodel

Selective KV-Cache Sharing to Mitigate Timing Side-Channels in LLM Inference

2025-08-11 · Kexin Chu, Zecheng Lin, Dawei Xiang, Zixu Shen 외 arxiv

Global KV-cache sharing is an effective optimization for accelerating large language model (LLM) inference, yet it introduces an API-visible timing side channel that lets adversaries infer sensitive user inputs from shar…

Enhanced Outsourced and Secure Inference for Tall Sparse Decision Trees

2025-05-04 · Andrew Quijano, Spyros T. Halkidis, Kevin Gallagher, Kemal Akkaya 외

A decision tree is an easy-to-understand tool that has been widely used for classification tasks. On the one hand, due to privacy concerns, there has been an urgent need to create privacy-preserving classifiers that conc…

Cloud ComputingPrivacy Preserving

Joint Timing Offset and Channel Estimation for Multi-user UFMC Uplink

2019-02-25

Universal filtered multi-carrier (UFMC), which groups and filters subcarriers before transmission, is a potential multi-carrier modulation technique investigated for the emerging Machine-Type Communications (MTC). Consid…

Unintended Memorization and Timing Attacks in Named Entity Recognition Models

2022-11-04 · Rana Salal Ali, Benjamin Zi Hao Zhao, Hassan Jameel Asghar, Tham Nguyen 외

Named entity recognition models (NER), are widely used for identifying named entities (e.g., individuals, locations, and other information) in text documents. Machine learning based NER models are increasingly being appl…

Memorizationnamed-entity-recognitionNamed Entity RecognitionNamed Entity Recognition (NER)+1