A Pragmatic Approach to Membership Inferences on Machine Learning Models

被引:32
|
作者
Long, Yunhui [1 ]
Wang, Lei [2 ]
Bu, Diyue [2 ]
Bindschaedler, Vincent [3 ]
Wang, Xiaofeng [2 ]
Tang, Haixu [2 ]
Gunter, Carl A. [1 ]
Chen, Kai [4 ,5 ]
机构
[1] Univ Illinois, Champaign, IL 61820 USA
[2] Indiana Univ, Bloomington, IN 47405 USA
[3] Univ Florida, Gainesville, FL 32611 USA
[4] Chinese Acad Sci, Inst Informat Engn, SKLOIS, Beijing, Peoples R China
[5] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
关键词
D O I
10.1109/EuroSP48549.2020.00040
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Membership Inference Attacks (MIAs) aim to determine the presence of a record in a machine learning model's training data by querying the model. Recent work has demonstrated the effectiveness of MIA on various machine learning models and corresponding defenses have been proposed. However, both attacks and defenses have focused on an adversary that indiscriminately attacks all the records without regard to the cost of false positives or negatives. In this work, we revisit membership inference attacks from the perspective of a pragmatic adversary who carefully selects targets and make predictions conservatively. We design a new evaluation methodology that allows us to evaluate the membership privacy risk at the level of individuals and not only in aggregate. We experimentally demonstrate that highly vulnerable records exist even when the aggregate attack precision is close to 50% (baseline). Specifically, on the MNIST dataset, our pragmatic adversary achieves a precision of 95.05% whereas the prior attack only achieves a precision of 51.7%.
引用
收藏
页码:521 / 534
页数:14
相关论文
共 50 条
  • [1] Membership Inference Attacks Against Machine Learning Models
    Shokri, Reza
    Stronati, Marco
    Song, Congzheng
    Shmatikov, Vitaly
    2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, : 3 - 18
  • [2] Membership Privacy for Machine Learning Models Through Knowledge Transfer
    Shejwalkar, Virat
    Houmansadr, Amir
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 9549 - 9557
  • [3] Learning models from data: the set membership approach
    Milanese, M
    PROCEEDINGS OF THE 1998 AMERICAN CONTROL CONFERENCE, VOLS 1-6, 1998, : 178 - 182
  • [4] A Tensor Approach to Learning Mixed Membership Community Models
    Anandkumar, Animashree
    Ge, Rong
    Hsu, Daniel
    Kakade, Sham M.
    JOURNAL OF MACHINE LEARNING RESEARCH, 2014, 15 : 2239 - 2312
  • [5] A tensor approach to learning mixed membership community models
    Anandkumar, Animashree
    Ge, Rong
    Hsu, Daniel
    Kakade, Sham M.
    Journal of Machine Learning Research, 2014, 15 : 2239 - 2312
  • [6] Performance analysis of various machine learning models for membership inference attack
    Karthikeyan, K.
    Padmanaban, K.
    Kavitha, Datchanamoorthy
    Sekhar, Jampani Chandra
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2023, 43 (04) : 232 - 245
  • [7] PCA-based membership inference attack for machine learning models
    Peng C.
    Gao T.
    Liu H.
    Ding H.
    Tongxin Xuebao/Journal on Communications, 2022, 43 (01): : 149 - 160
  • [8] Towards Securing Machine Learning Models Against Membership Inference Attacks
    Ben Hamida, Sana
    Mrabet, Hichem
    Belguith, Sana
    Alhomoud, Adeeb
    Jemai, Abderrazak
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 70 (03): : 4897 - 4919
  • [9] Pragmatic inferences in context: learning to interpret contrastive prosody
    Kurumada, Chigusa
    Clark, Eve V.
    JOURNAL OF CHILD LANGUAGE, 2017, 44 (04) : 850 - 880
  • [10] Influence of Membership Function and Degree on Sorghum Growth Prediction Models in Machine Learning
    Rahman, Abdul
    Ermatita
    Budianta, Dedik
    Abdiansah
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (12) : 232 - 241