EAR: An Enhanced Adversarial Regularization Approach against Membership Inference Attacks

被引:2
|
作者
Hu, Hongsheng [1 ]
Salcic, Zoran [1 ]
Dobbie, Gillian [2 ]
Chen, Yi [3 ]
Zhang, Xuyun [4 ]
机构
[1] Univ Auckland, Dept ECE, Auckland, New Zealand
[2] Univ Auckland, Sch Comp Sci, Auckland, New Zealand
[3] Southwest Jiaotong Univ, Sch Informat Sci & Technol, Chengdu, Peoples R China
[4] Macquarie Univ, Dept Comp, Sydney, NSW, Australia
关键词
Data privacy; Membership inference attacks; Adversarial regularization; Machine learning;
D O I
10.1109/IJCNN52387.2021.9534381
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Membership inference attacks on a machine learning model aim to determine whether a given data record is a member of the training set. They pose severe privacy risks to individuals, e.g., identifying an individual's participation in a hospital's health analytic training set reveals that this individual was once a patient in that hospital. Adversarial regularization (AR) is one of the state-of-the-art defense methods that mitigate such attacks while preserving a model's prediction accuracy. AR adds membership inference attacks as a new regularization term to the target model during the training process. It is an adversarial training algorithm that is trained on a defended model which is essentially the same as training the generator of generative adversarial networks (GANs). We observe that many GAN variants are able to generate higher quality samples and offer more stability during the training phase than GANs. However, whether these GAN variants are available to improve the effectiveness of AR has not been investigated. In this paper, we propose an enhanced adversarial regularization (EAR) method based on Least Square GANs (LSGANs). The new EAR surpasses the existing AR in offering more powerful defensive ability while preserving the same prediction accuracy of the protected classifiers. We systematically evaluate EAR on five datasets with different target classifiers under four different attack methods and compare it with four other defense methods. We experimentally show that our new method performs the best among other defense methods.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] MiDA: Membership inference attacks against domain adaptation
    Zhang, Yuanjie
    Zhao, Lingchen
    Wang, Qian
    ISA TRANSACTIONS, 2023, 141 : 103 - 112
  • [22] Membership inference attacks against synthetic health data
    Zhang, Ziqi
    Yan, Chao
    Malin, Bradley A.
    JOURNAL OF BIOMEDICAL INFORMATICS, 2022, 125
  • [23] Assessment of data augmentation, dropout with L2 Regularization and differential privacy against membership inference attacks
    Ben Hamida, Sana
    Mrabet, Hichem
    Chaieb, Faten
    Jemai, Abderrazak
    MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 83 (15) : 44455 - 44484
  • [24] Assessment of data augmentation, dropout with L2 Regularization and differential privacy against membership inference attacks
    Sana Ben Hamida
    Hichem Mrabet
    Faten Chaieb
    Abderrazak Jemai
    Multimedia Tools and Applications, 2024, 83 : 44455 - 44484
  • [25] Use the Spear as a Shield: An Adversarial Example Based Privacy-Preserving Technique Against Membership Inference Attacks
    Xue, Mingfu
    Yuan, Chengxiang
    He, Can
    Wu, Yinghao
    Wu, Zhiyu
    Zhang, Yushu
    Liu, Zhe
    Liu, Weiqiang
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2023, 11 (01) : 153 - 169
  • [26] Fingerprint membership and identity inference against generative adversarial networks
    Cavasin, Saverio
    Mari, Daniele
    Milani, Simone
    Conti, Mauro
    PATTERN RECOGNITION LETTERS, 2024, 185 : 184 - 189
  • [27] TOWARDS MODEL QUANTIZATION ON THE RESILIENCE AGAINST MEMBERSHIP INFERENCE ATTACKS
    Kowalski, Charles
    Famili, Azadeh
    Lao, Yingjie
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 3646 - 3650
  • [28] Membership inference attacks against transfer learning for generalized model
    Chen, Jinyin
    Shangguan, Wenchang
    Zhang, Jingjing
    Zheng, Haibin
    Zheng, Yayu
    Zhang, Xu-Hong
    Tongxin Xuebao/Journal on Communications, 2021, 42 (10): : 197 - 210
  • [29] Membership Inference Attacks Against Robust Graph Neural Network
    Liu, Zhengyang
    Zhang, Xiaoyu
    Chen, Chenyang
    Lin, Shen
    Li, Jingjin
    CYBERSPACE SAFETY AND SECURITY, CSS 2022, 2022, 13547 : 259 - 273
  • [30] Debiasing Learning for Membership Inference Attacks Against Recommender Systems
    Wang, Zihan
    Huang, Na
    Sun, Fei
    Ren, Pengjie
    Chen, Zhumin
    Luo, Hengliang
    de Rijke, Maarten
    Ren, Zhaochun
    PROCEEDINGS OF THE 28TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2022, 2022, : 1959 - 1968