Label-Only Membership Inference Attack Based on Model Explanation

被引:0
|
作者
Ma, Yao [1 ]
Zhai, Xurong [1 ]
Yu, Dan [1 ]
Yang, Yuli [1 ]
Wei, Xingyu [2 ]
Chen, Yongle [1 ]
机构
[1] Taiyuan Univ Technol, Coll Comp Sci & Technol, Jinzhong 030600, Peoples R China
[2] Tsinghua Univ, Res Ctr Identificat & Resolut Syst, Jiashan Novat Ctr, Yangtze Delta Reg Inst, Beijing 314100, Zhejiang, Peoples R China
关键词
Machine Learning; Membership Inference Attack; Forgettable Examples; Feature Attribution; Confidence Estimate;
D O I
10.1007/s11063-024-11682-1
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
It is well known that machine learning models (e.g., image recognition) can unintentionally leak information about the training set. Conventional membership inference relies on posterior vectors, and this task becomes extremely difficult when the posterior is masked. However, current label-only membership inference attacks require a large number of queries during the generation of adversarial samples, and thus incorrect inference generates a large number of invalid queries. Therefore, we introduce a label-only membership inference attack based on model explanations. It can transform a label-only attack into a traditional membership inference attack by observing neighborhood consistency and perform fine-grained membership inference for vulnerable samples. We use feature attribution to simplify the high-dimensional neighborhood sampling process, quickly identify decision boundaries and recover a posteriori vectors. It also compares different privacy risks faced by different samples through finding vulnerable samples. The method is validated on CIFAR-10, CIFAR-100 and MNIST datasets. The results show that membership attributes can be identified even using a simple sampling method. Furthermore, vulnerable samples expose the model to greater privacy risks.
引用
收藏
页数:17
相关论文
共 50 条
  • [41] Membership inference attack on differentially private block coordinate descent
    Riaz S.
    Ali S.
    Wang G.
    Latif M.A.
    Iqbal M.Z.
    PeerJ Computer Science, 2023, 9
  • [42] Membership inference attack on differentially private block coordinate descent
    Riaz, Shazia
    Ali, Saqib
    Wang, Guojun
    Latif, Muhammad Ahsan
    Iqbal, Muhammad Zafar
    PEERJ COMPUTER SCIENCE, 2023, 9
  • [43] Against Membership Inference Attack: Pruning is All You Need
    Wang, Yijue
    Wang, Chenghong
    Wang, Zigeng
    Zhou, Shanglin
    Liu, Hang
    Bi, Jinbo
    Ding, Caiwen
    Rajasekaran, Sanguthevar
    PROCEEDINGS OF THE THIRTIETH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2021, 2021, : 3141 - 3147
  • [44] Mitigation of Membership Inference Attack by Knowledge Distillation on Federated Learning
    Ueda, Rei
    Nakai, Tsunato
    Yoshida, Kota
    Fujino, Takeshi
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2025, E108A (03) : 267 - 279
  • [45] Query-efficient label-only attacks against black-box machine learning models
    Ren, Yizhi
    Zhou, Qi
    Wang, Zhen
    Wu, Ting
    Wu, Guohua
    Choo, Kim-Kwang Raymond
    COMPUTERS & SECURITY, 2020, 90
  • [46] CS-MIA: Membership inference attack based on prediction confidence series in federated learning
    Gu, Yuhao
    Bai, Yuebin
    Xu, Shubin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 67
  • [47] HP-MIA: A novel membership inference attack scheme for high membership prediction precision
    Chen, Shi
    Wang, Wennan
    Zhong, Yubin
    Ying, Zuobin
    Tang, Weixuan
    Pan, Zijie
    COMPUTERS & SECURITY, 2024, 136
  • [48] Black-box membership inference attacks based on shadow model
    Han Zhen
    Zhou Wen'an
    Han Xiaoxuan
    Wu Jie
    TheJournalofChinaUniversitiesofPostsandTelecommunications, 2024, 31 (04) : 1 - 16
  • [49] Black-box membership inference attacks based on shadow model
    Zhen, Han
    Wen’An, Zhou
    Xiaoxuan, Han
    Jie, Wu
    Journal of China Universities of Posts and Telecommunications, 2024, 31 (04): : 1 - 16
  • [50] Enhanced Mixup Training: a Defense Method Against Membership Inference Attack
    Chen, Zongqi
    Li, Hongwei
    Hao, Meng
    Xu, Guowen
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, ISPEC 2021, 2021, 13107 : 32 - 45