Learning-Based Difficulty Calibration for Enhanced Membership Inference Attacks

被引:0
|
作者
Shi, Haonan [1 ]
Ouyang, Tu [1 ]
Wang, An [1 ]
机构
[1] Case Western Reserve Univ, Cleveland, OH 44106 USA
关键词
D O I
10.1109/EuroSP60621.2024.00012
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Machine learning models, in particular deep neural networks, are currently an integral part of various applications, from healthcare to finance. However, using sensitive data to train these models raises concerns about privacy and security. One method that has emerged to verify if the trained models are privacy-preserving is Membership Inference Attacks (MIA), which allows adversaries to determine whether a specific data point was part of a model's training dataset. While a series of MIAs have been proposed in the literature, only a few can achieve high True Positive Rates (TPR) in the low False Positive Rate (FPR) region (0.01% similar to 1%). This is a crucial factor to consider for an MIA to be practically useful in real-world settings. In this paper, we present a novel approach to MIA that is aimed at significantly improving TPR at low FPRs. Our method, named learning-based difficulty calibration for MIA (LDC-MIA), characterizes data records by their hardness levels using a neural network classifier to determine membership. The experiment results show that LDC-MIA can improve TPR at low FPR by up to 4x compared to the other difficulty calibration-based MIAs. It also has the highest Area Under ROC curve (AUC) across all datasets. Our method's cost is comparable with most of the existing MIAs, but is orders of magnitude more efficient than one of the state-of-the-art methods, LiRA, while achieving similar performance.
引用
收藏
页码:62 / 77
页数:16
相关论文
共 50 条
  • [21] Security for Machine Learning-based Systems: Attacks and Challenges during Training and Inference
    Khalid, Faiq
    Hanif, Muhammad Abdullah
    Rehman, Semeen
    Shafique, Muhammad
    2018 INTERNATIONAL CONFERENCE ON FRONTIERS OF INFORMATION TECHNOLOGY (FIT 2018), 2018, : 327 - 332
  • [22] Link Membership Inference Attacks against Unsupervised Graph Representation Learning
    Wang, Xiuling
    Wang, Wendy Hui
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 477 - 491
  • [23] Assessing the Impact of Membership Inference Attacks on Classical Machine Learning Algorithms
    Ruiz de Arcaute, Gonzalo Martinez
    Alberto Hernandez, Jose
    Reviriego, Pedro
    2022 18TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS (DRCN), 2022,
  • [24] Synthetic image learning: Preserving performance and preventing Membership Inference Attacks
    Lomurno, Eugenio
    Matteucci, Matteo
    PATTERN RECOGNITION LETTERS, 2025, 190 : 52 - 58
  • [25] Towards Securing Machine Learning Models Against Membership Inference Attacks
    Ben Hamida, Sana
    Mrabet, Hichem
    Belguith, Sana
    Alhomoud, Adeeb
    Jemai, Abderrazak
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 70 (03): : 4897 - 4919
  • [26] Membership Inference Attacks against MemGuard
    Niu, Ben
    Chen, Yahong
    Zhang, Likun
    Li, Fenghua
    2020 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2020,
  • [27] LDL: A Defense for Label-Based Membership Inference Attacks
    Rajabi, Arezoo
    Sahabandu, Dinuka
    Niu, Luyao
    Ramasubramanian, Bhaskar
    Poovendran, Radha
    PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 95 - 108
  • [28] Attribute-Based Membership Inference Attacks and Defenses on GANs
    Sun, Hui
    Zhu, Tianqing
    Li, Jie
    Ji, Shoulin
    Zhou, Wanlei
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 2376 - 2393
  • [29] Membership Inference Attacks: Analysis and Mitigation
    Shuvo, Md Shamimur Rahman
    Alhadidi, Dima
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1411 - 1420
  • [30] Defenses to Membership Inference Attacks: A Survey
    Hu, Li
    Yan, Anli
    Yan, Hongyang
    Li, Jin
    Huang, Teng
    Zhang, Yingying
    Dong, Changyu
    Yang, Chunsheng
    ACM COMPUTING SURVEYS, 2024, 56 (04)