Black-box membership inference attacks based on shadow model

被引:0
|
作者
Han Zhen
Zhou Wen'an
Han Xiaoxuan
Wu Jie
机构
[1] SchoolofComputerScience,BeijingUniversityofPostsandTelecommunications
关键词
D O I
暂无
中图分类号
TP181 [自动推理、机器学习]; TP309 [安全保密];
学科分类号
081201 ; 0839 ; 1402 ;
摘要
Membership inference attacks on machine learning models have drawn significant attention. While current research primarily utilizes shadow modeling techniques, which require knowledge of the target model and training data, practical scenarios involve black-box access to the target model with no available information. Limited training data further complicate the implementation of these attacks. In this paper, we experimentally compare common data enhancement schemes and propose a data synthesis framework based on the variational autoencoder generative adversarial network(VAE-GAN) to extend the training data for shadow models. Meanwhile, this paper proposes a shadow model training algorithm based on adversarial training to improve the shadow model's ability to mimic the predicted behavior of the target model when the target model's information is unknown. By conducting attack experiments on different models under the black-box access setting, this paper verifies the effectiveness of the VAE-GAN-based data synthesis framework for improving the accuracy of membership inference attack. Furthermore, we verify that the shadow model, trained by using the adversarial training approach, effectively improves the degree of mimicking the predicted behavior of the target model. Compared with existing research methods, the method proposed in this paper achieves a 2% improvement in attack accuracy and delivers better attack performance.
引用
收藏
页码:1 / 16
页数:16
相关论文
共 50 条
  • [1] Black-box membership inference attacks based on shadow model
    Zhen, Han
    Wen’An, Zhou
    Xiaoxuan, Han
    Jie, Wu
    Journal of China Universities of Posts and Telecommunications, 2024, 31 (04): : 1 - 16
  • [2] Black-Box Based Limited Query Membership Inference Attack
    Zhang, Yu
    Zhou, Huaping
    Wang, Pengyan
    Yang, Gaoming
    IEEE ACCESS, 2022, 10 : 55459 - 55468
  • [3] MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples
    Jia, Jinyuan
    Salem, Ahmed
    Backes, Michael
    Zhang, Yang
    Gong, Neil Zhenqiang
    PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 259 - 274
  • [4] GanNoise: Defending against black-box membership inference attacks by countering noise generation
    Liang, Jiaming
    Huang, Teng
    Luo, Zidan
    Li, Dan
    Li, Yunhao
    Ding, Ziyu
    2023 INTERNATIONAL CONFERENCE ON DATA SECURITY AND PRIVACY PROTECTION, DSPP, 2023, : 32 - 40
  • [5] GANMIA: GAN-based Black-box Membership Inference Attack
    Bai, Yang
    Chen, Degang
    Chen, Ting
    Fan, Mingyu
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2021), 2021,
  • [6] Gradient-Leaks: Enabling Black-Box Membership Inference Attacks Against Machine Learning Models
    Liu, Gaoyang
    Xu, Tianlong
    Zhang, Rui
    Wang, Zixiong
    Wang, Chen
    Liu, Ling
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 427 - 440
  • [7] White-box vs Black-box: Bayes Optimal Strategies for Membership Inference
    Sablayrolles, Alexandre
    Douze, Matthijs
    Ollivier, Yann
    Schmid, Cordelia
    Jegou, Nerve
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [8] Reinforcement Learning-Based Black-Box Model Inversion Attacks
    Han, Gyojin
    Choi, Jaehyun
    Lee, Haeil
    Kim, Junmo
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 20504 - 20513
  • [9] Constructive membership in black-box groups
    Holmes, P. E.
    Linton, S. A.
    O'Brien, E. A.
    Ryba, A. J. E.
    Wilson, R. A.
    JOURNAL OF GROUP THEORY, 2008, 11 (06) : 747 - 763
  • [10] Simple Black-box Adversarial Attacks
    Guo, Chuan
    Gardner, Jacob R.
    You, Yurong
    Wilson, Andrew Gordon
    Weinberger, Kilian Q.
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97