Label-Only Membership Inference Attack Based on Model Explanation

被引:0
|
作者
Ma, Yao [1 ]
Zhai, Xurong [1 ]
Yu, Dan [1 ]
Yang, Yuli [1 ]
Wei, Xingyu [2 ]
Chen, Yongle [1 ]
机构
[1] Taiyuan Univ Technol, Coll Comp Sci & Technol, Jinzhong 030600, Peoples R China
[2] Tsinghua Univ, Res Ctr Identificat & Resolut Syst, Jiashan Novat Ctr, Yangtze Delta Reg Inst, Beijing 314100, Zhejiang, Peoples R China
关键词
Machine Learning; Membership Inference Attack; Forgettable Examples; Feature Attribution; Confidence Estimate;
D O I
10.1007/s11063-024-11682-1
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
It is well known that machine learning models (e.g., image recognition) can unintentionally leak information about the training set. Conventional membership inference relies on posterior vectors, and this task becomes extremely difficult when the posterior is masked. However, current label-only membership inference attacks require a large number of queries during the generation of adversarial samples, and thus incorrect inference generates a large number of invalid queries. Therefore, we introduce a label-only membership inference attack based on model explanations. It can transform a label-only attack into a traditional membership inference attack by observing neighborhood consistency and perform fine-grained membership inference for vulnerable samples. We use feature attribution to simplify the high-dimensional neighborhood sampling process, quickly identify decision boundaries and recover a posteriori vectors. It also compares different privacy risks faced by different samples through finding vulnerable samples. The method is validated on CIFAR-10, CIFAR-100 and MNIST datasets. The results show that membership attributes can be identified even using a simple sampling method. Furthermore, vulnerable samples expose the model to greater privacy risks.
引用
收藏
页数:17
相关论文
共 50 条
  • [31] Similarity-Based Label Inference Attack Against Training and Inference of Split Learning
    Liu, Junlin
    Lyu, Xinchen
    Cui, Qimei
    Tao, Xiaofeng
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 2881 - 2895
  • [32] Practical Membership Inference Attack Against Collaborative Inference in Industrial IoT
    Chen, Hanxiao
    Li, Hongwei
    Dong, Guishan
    Hao, Meng
    Xu, Guowen
    Huang, Xiaoming
    Liu, Zhe
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (01) : 477 - 487
  • [33] GANMIA: GAN-based Black-box Membership Inference Attack
    Bai, Yang
    Chen, Degang
    Chen, Ting
    Fan, Mingyu
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2021), 2021,
  • [34] Similarity Distribution based Membership Inference Attack on Person Re-Identification
    Gao, Junyao
    Jiang, Xinyang
    Zhang, Huishuai
    Yang, Yifan
    Dou, Shuguang
    Li, Dongsheng
    Miao, Duoqian
    Deng, Cheng
    Zhao, Cairong
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 12, 2023, : 14820 - 14828
  • [35] Preserving Privacy in GANs Against Membership Inference Attack
    Shateri, Mohammadhadi
    Messina, Francisco
    Labeau, Fabrice
    Piantanida, Pablo
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1728 - 1743
  • [36] Membership Inference Attack Against Principal Component Analysis
    Zari, Oualid
    Parra-Arnau, Javier
    Unsal, Ayse
    Strufe, Thorsten
    Onen, Melek
    PRIVACY IN STATISTICAL DATABASES, PSD 2022, 2022, 13463 : 269 - 282
  • [37] Towards a Game-Theoretic Understanding of Explanation-Based Membership Inference Attacks
    Kumari, Kavita
    Jadliwala, Murtuza
    Jha, Sumit Kumar
    Maiti, Anindya
    DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2024, 2025, 14908 : 263 - 283
  • [38] Subject-Level Membership Inference Attack via Data Augmentation and Model Discrepancy
    Liu, Yimin
    Jiang, Peng
    Zhu, Liehuang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5848 - 5859
  • [39] An Auto-Encoder based Membership Inference Attack against Generative Adversarial Network
    Azadmanesh, Maryam
    Ghahfarokhi, Behrouz Shahgholi
    Talouki, Maede Ashouri
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 15 (02): : 240 - 253
  • [40] Practical Blind Membership Inference Attack via Differential Comparisons
    Hui, Bo
    Yang, Yuchen
    Yuan, Haolin
    Burlina, Philippe
    Gong, Neil Zhenqiang
    Cao, Yinzhi
    28TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2021), 2021,