A Pragmatic Approach to Membership Inferences on Machine Learning Models

被引:32
|
作者
Long, Yunhui [1 ]
Wang, Lei [2 ]
Bu, Diyue [2 ]
Bindschaedler, Vincent [3 ]
Wang, Xiaofeng [2 ]
Tang, Haixu [2 ]
Gunter, Carl A. [1 ]
Chen, Kai [4 ,5 ]
机构
[1] Univ Illinois, Champaign, IL 61820 USA
[2] Indiana Univ, Bloomington, IN 47405 USA
[3] Univ Florida, Gainesville, FL 32611 USA
[4] Chinese Acad Sci, Inst Informat Engn, SKLOIS, Beijing, Peoples R China
[5] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
关键词
D O I
10.1109/EuroSP48549.2020.00040
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Membership Inference Attacks (MIAs) aim to determine the presence of a record in a machine learning model's training data by querying the model. Recent work has demonstrated the effectiveness of MIA on various machine learning models and corresponding defenses have been proposed. However, both attacks and defenses have focused on an adversary that indiscriminately attacks all the records without regard to the cost of false positives or negatives. In this work, we revisit membership inference attacks from the perspective of a pragmatic adversary who carefully selects targets and make predictions conservatively. We design a new evaluation methodology that allows us to evaluate the membership privacy risk at the level of individuals and not only in aggregate. We experimentally demonstrate that highly vulnerable records exist even when the aggregate attack precision is close to 50% (baseline). Specifically, on the MNIST dataset, our pragmatic adversary achieves a precision of 95.05% whereas the prior attack only achieves a precision of 51.7%.
引用
收藏
页码:521 / 534
页数:14
相关论文
共 50 条
  • [41] A hybrid approach based machine learning models in electricity markets
    Gomez, William
    Wang, Fu-Kwun
    Lo, Shih-Che
    ENERGY, 2024, 289
  • [42] A Machine Learning Approach to Policy Optimization in System Dynamics Models
    Chen, Yao-Tsung
    Tu, Yi-Ming
    Jeng, Bingchiang
    SYSTEMS RESEARCH AND BEHAVIORAL SCIENCE, 2011, 28 (04) : 369 - 390
  • [43] Machine learning classification approach for asthma prediction models in children
    Raphael Henshaw Ekpo
    Victor Chukwudi Osamor
    Ambrose A. Azeta
    Excellent Ikeakanam
    Beatrice Opeyemi Amos
    Health and Technology, 2023, 13 : 1 - 10
  • [44] A Pragmatic Approach on Epistemology, Teaching, and Learning
    Ostman, Leif
    Wickman, Per-Olof
    SCIENCE EDUCATION, 2014, 98 (03) : 375 - 382
  • [45] ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models
    Salem, Ahmed
    Zhang, Yang
    Humbert, Mathias
    Berrang, Pascal
    Fritz, Mario
    Backes, Michael
    26TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2019), 2019,
  • [46] A Pragmatic Machine Learning Approach to Quantify Tumor-Infiltrating Lymphocytes in Whole Slide Images
    Shvetsov, Nikita
    Gronnesby, Morten
    Pedersen, Edvard
    Mollersen, Kajsa
    Busund, Lill-Tove Rasmussen
    Schwienbacher, Ruth
    Bongo, Lars Ailo
    Kilvaer, Thomas Karsten
    CANCERS, 2022, 14 (12)
  • [47] A Pragmatic Signal Processing Approach for Nurse Care Activity Recognition Using Classical Machine Learning
    Faisal, Md Ahasan Atick
    Siraj, Md Sadman
    Abdullah, Md Tahmeed
    Shahid, Omar
    Abir, Farhan Fuad
    Ahad, M. A. R.
    UBICOMP/ISWC '20 ADJUNCT: PROCEEDINGS OF THE 2020 ACM INTERNATIONAL JOINT CONFERENCE ON PERVASIVE AND UBIQUITOUS COMPUTING AND PROCEEDINGS OF THE 2020 ACM INTERNATIONAL SYMPOSIUM ON WEARABLE COMPUTERS, 2020, : 396 - 401
  • [48] Mitigating Membership Inference Attacks in Machine Learning as a Service
    Bouhaddi, Myria
    Adi, Kamel
    2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 262 - 268
  • [49] A Survey on Membership Inference Attacks Against Machine Learning
    Bai, Yang
    Chen, Ting
    Fan, Mingyu
    International Journal of Network Security, 2021, 23 (04) : 685 - 697
  • [50] Effects of repetition on memory for pragmatic inferences
    McDermott, Kathleen B.
    Chan, Jason C. K.
    MEMORY & COGNITION, 2006, 34 (06) : 1273 - 1284