EAR: An Enhanced Adversarial Regularization Approach against Membership Inference Attacks

被引:2
|
作者
Hu, Hongsheng [1 ]
Salcic, Zoran [1 ]
Dobbie, Gillian [2 ]
Chen, Yi [3 ]
Zhang, Xuyun [4 ]
机构
[1] Univ Auckland, Dept ECE, Auckland, New Zealand
[2] Univ Auckland, Sch Comp Sci, Auckland, New Zealand
[3] Southwest Jiaotong Univ, Sch Informat Sci & Technol, Chengdu, Peoples R China
[4] Macquarie Univ, Dept Comp, Sydney, NSW, Australia
关键词
Data privacy; Membership inference attacks; Adversarial regularization; Machine learning;
D O I
10.1109/IJCNN52387.2021.9534381
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Membership inference attacks on a machine learning model aim to determine whether a given data record is a member of the training set. They pose severe privacy risks to individuals, e.g., identifying an individual's participation in a hospital's health analytic training set reveals that this individual was once a patient in that hospital. Adversarial regularization (AR) is one of the state-of-the-art defense methods that mitigate such attacks while preserving a model's prediction accuracy. AR adds membership inference attacks as a new regularization term to the target model during the training process. It is an adversarial training algorithm that is trained on a defended model which is essentially the same as training the generator of generative adversarial networks (GANs). We observe that many GAN variants are able to generate higher quality samples and offer more stability during the training phase than GANs. However, whether these GAN variants are available to improve the effectiveness of AR has not been investigated. In this paper, we propose an enhanced adversarial regularization (EAR) method based on Least Square GANs (LSGANs). The new EAR surpasses the existing AR in offering more powerful defensive ability while preserving the same prediction accuracy of the protected classifiers. We systematically evaluate EAR on five datasets with different target classifiers under four different attack methods and compare it with four other defense methods. We experimentally show that our new method performs the best among other defense methods.
引用
收藏
页数:8
相关论文
共 50 条
  • [31] Membership Inference Attacks Against Incremental Learning in IoT Devices
    Zhang, Xianglong
    Zhang, Huanle
    Zhang, Guoming
    Yang, Yanni
    Li, Feng
    Fan, Lisheng
    Huang, Zhijian
    Cheng, Xiuzhen
    Hu, Pengfei
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2025, 24 (05) : 4006 - 4021
  • [32] Defending Against Membership Inference Attacks With High Utility by GAN
    Hu, Li
    Li, Jin
    Lin, Guanbiao
    Peng, Shiyu
    Zhang, Zhenxin
    Zhang, Yingying
    Dong, Changyu
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2144 - 2157
  • [33] LocMIA: Membership Inference Attacks Against Aggregated Location Data
    Zhang, Guanglin
    Zhang, Anqi
    Zhao, Ping
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (12) : 11778 - 11788
  • [34] On the Difficulty of Membership Inference Attacks
    Rezaei, Shahbaz
    Liu, Xin
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 7888 - 7896
  • [35] DAMIA: Leveraging Domain Adaptation as a Defense Against Membership Inference Attacks
    Huang, Hongwei
    Luo, Weiqi
    Zeng, Guoqiang
    Weng, Jian
    Zhang, Yue
    Yang, Anjia
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (05) : 3183 - 3199
  • [36] Link Membership Inference Attacks against Unsupervised Graph Representation Learning
    Wang, Xiuling
    Wang, Wendy Hui
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 477 - 491
  • [37] Membership Inference Attacks against Language Models via Neighbourhood Comparison
    Mattern, Justus
    Mireshghallah, Fatemehsadat
    Jin, Zhijing
    Schoelkopf, Bernhard
    Sachan, Mrinmaya
    Berg-Kirkpatrick, Taylor
    FINDINGS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2023), 2023, : 11330 - 11343
  • [38] Learning-Based Difficulty Calibration for Enhanced Membership Inference Attacks
    Shi, Haonan
    Ouyang, Tu
    Wang, An
    9TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, EUROS&P 2024, 2024, : 62 - 77
  • [39] Membership Inference Attacks against Synthetic Data through Overfitting Detection
    van Breugel, Boris
    Sun, Hao
    Qian, Zhaozhi
    van der Schaar, Mihaela
    INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 206, 2023, 206
  • [40] Membership Inference Attacks Against Self-supervised Speech Models
    Tseng, Wei-Cheng
    Kao, Wei-Tsung
    Lee, Hung-yi
    INTERSPEECH 2022, 2022, : 5040 - 5044