Privacy-preserving generative framework for images against membership inference attacks

被引:2
|
作者
Yang, Ruikang [1 ,2 ]
Ma, Jianfeng [1 ,2 ]
Miao, Yinbin [1 ,2 ]
Ma, Xindi [1 ,2 ]
机构
[1] Xidian Univ, State Key Lab Integrated Serv Networks ISN, Xian, Peoples R China
[2] Xidian Univ, Sch Cyber Engn, Xian, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1049/cmu2.12507
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Machine learning has become an integral part of modern intelligent systems in all aspects of life. Membership inference attacks (MIAs), as the significant model attacks, also jeopardize the privacy of the intelligent systems. Previous works on defending MIAs concentrate on the model output perturbation or tampering with the training process. However, data and model reuse are common in intelligent systems, which results in the lack of scalability of previous defending works. This paper proposes a new privacy-preserving framework for images to transform source data into synthetic data to train models against MIAs. The synthetic data makes it easy to defend MIAs during data and model reuse to improve the scheme's scalability. The framework generates synthetic data satisfying differential privacy through the variational autoencoder model's information extraction and data generation capabilities to improve model accuracy. A noise addition mechanism with metric privacy for the latent code generated from source data is proposed, where noise is the product of Gamma-distribution and unit hyper-sphere samples. Moreover, it is proved that the synthetic data also satisfies metric privacy. The experimental evaluations demonstrate that the framework reduces MIAs' attack accuracy to about 0.5 and maintains higher utility than DP-SGD under the same setting.
引用
收藏
页码:45 / 62
页数:18
相关论文
共 50 条
  • [1] Enhancing Deep Learning Model Privacy Against Membership Inference Attacks Using Privacy-Preserving Oversampling
    Subhasish Ghosh
    Amit Kr Mandal
    Agostino Cortesi
    SN Computer Science, 6 (4)
  • [2] Use the Spear as a Shield: An Adversarial Example Based Privacy-Preserving Technique Against Membership Inference Attacks
    Xue, Mingfu
    Yuan, Chengxiang
    He, Can
    Wu, Yinghao
    Wu, Zhiyu
    Zhang, Yushu
    Liu, Zhe
    Liu, Weiqiang
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2023, 11 (01) : 153 - 169
  • [3] Efficient Privacy-Preserving Federated Learning Against Inference Attacks for IoT
    Miao, Yifeng
    Chen, Siguang
    2023 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, WCNC, 2023,
  • [4] Privacy-Preserving Network Embedding Against Private Link Inference Attacks
    Han, Xiao
    Yang, Yuncong
    Wang, Leye
    Wu, Junjie
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (02) : 847 - 859
  • [5] A Privacy-preserving Framework for Rank Inference
    Gao, Yunpeng
    Yan, Tong
    Zhang, Nan
    2017 1ST IEEE SYMPOSIUM ON PRIVACY-AWARE COMPUTING (PAC), 2017, : 180 - 181
  • [6] A Verifiable Privacy-Preserving Federated Learning Framework Against Collusion Attacks
    Chen, Yange
    He, Suyu
    Wang, Baocang
    Feng, Zhanshen
    Zhu, Guanghui
    Tian, Zhihong
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2025, 24 (05) : 3918 - 3934
  • [7] Friendship links-based privacy-preserving algorithm against inference attacks
    Shen, Jiawei
    Tian, Junfeng
    Wang, Ziyuan
    Cai, Hongyun
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (10) : 9363 - 9375
  • [8] Privacy-preserving inference resistant to model extraction attacks
    Byun, Junyoung
    Choi, Yujin
    Lee, Jaewook
    Park, Saerom
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 256
  • [9] Preserving Privacy in GANs Against Membership Inference Attack
    Shateri, Mohammadhadi
    Messina, Francisco
    Labeau, Fabrice
    Piantanida, Pablo
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1728 - 1743
  • [10] Inf2Guard: An Information-Theoretic Framework for Learning Privacy-Preserving Representations against Inference Attacks
    Noorbakhsh, Sayedeh Leila
    Zhang, Binghui
    Hong, Yuan
    Wang, Binghui
    PROCEEDINGS OF THE 33RD USENIX SECURITY SYMPOSIUM, SECURITY 2024, 2024, : 2405 - 2422