Label-Only Membership Inference Attacks

被引:0
|
作者
Choquette-Choo, Christopher A. [1 ,2 ]
Tramer, Florian [3 ]
Carlini, Nicholas [4 ]
Papernot, Nicolas [1 ,2 ]
机构
[1] Univ Toronto, Toronto, ON, Canada
[2] Vector Inst, Toronto, ON, Canada
[3] Stanford Univ, Stanford, CA 94305 USA
[4] Google, Mountain View, CA 94043 USA
基金
加拿大自然科学与工程研究理事会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Membership inference is one of the simplest privacy threats faced by machine learning models that are trained on private sensitive data. In this attack, an adversary infers whether a particular point was used to train the model, or not, by observing the model's predictions. Whereas current attack methods all require access to the model's predicted confidence score, we introduce a labelonly attack that instead evaluates the robustness of the model's predicted (hard) labels under perturbations of the input, to infer membership. Our label-only attack is not only as-effective as attacks requiring access to confidence scores, it also demonstrates that a class of defenses against membership inference, which we call "confidence masking" because they obfuscate the confidence scores to thwart attacks, are insufficient to prevent the leakage of private information. Our experiments show that training with differential privacy or strong l(2) regularization are the only current defenses that meaningfully decrease leakage of private information, even for points that are outliers of the training distribution.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] Label-Only Membership Inference Attacks and Defenses in Semantic Segmentation Models
    Zhang, Guangsheng
    Liu, Bo
    Zhu, Tianqing
    Ding, Ming
    Zhou, Wanlei
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (02) : 1435 - 1449
  • [2] Label-only membership inference attacks on machine unlearning without dependence of posteriors
    Lu, Zhaobo
    Liang, Hai
    Zhao, Minghao
    Lv, Qingzhe
    Liang, Tiancai
    Wang, Yilei
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (11) : 9424 - 9441
  • [3] Optimizing Label-Only Membership Inference Attacks by Global Relative Decision Boundary Distances
    Xu, Jiacheng
    Hu, Jianpeng
    Yu, Chunqing
    Tan, Chengxiang
    INFORMATION SECURITY, PT I, ISC 2024, 2025, 15257 : 107 - 126
  • [4] Label-Only Membership Inference Attack Based on Model Explanation
    Ma, Yao
    Zhai, Xurong
    Yu, Dan
    Yang, Yuli
    Wei, Xingyu
    Chen, Yongle
    NEURAL PROCESSING LETTERS, 2024, 56 (05)
  • [5] Label-Only Membership Inference Attack Against Federated Distillation
    Wang, Xi
    Zhao, Yanchao
    Zhang, Jiale
    Chen, Bing
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT II, 2024, 14488 : 394 - 410
  • [6] POSTER: Double-Dip: Thwarting Label-Only Membership Inference Attacks with Transfer Learning and Randomization
    Rajabi, Arezoo
    Pimple, Reeya
    Janardhanan, Aiswarya
    Asokraj, Surudhi
    Ramasubramanian, Bhaskar
    Poovendran, Radha
    PROCEEDINGS OF THE 19TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ACM ASIACCS 2024, 2024, : 1937 - 1939
  • [7] Membership Leakage in Label-Only Exposures
    Li, Zheng
    Zhang, Yang
    CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 880 - 895
  • [8] Label-Only Model Inversion Attacks: Attack With the Least Information
    Zhu, Tianqing
    Ye, Dayong
    Zhou, Shuai
    Liu, Bo
    Zhou, Wanlei
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 991 - 1005
  • [9] Label-Only Model Inversion Attacks via Boundary Repulsion
    Kahla, Mostafa
    Chen, Si
    Just, Hoang Anh
    Jia, Ruoxi
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15025 - 15033
  • [10] Label-Only Model Inversion Attacks via Knowledge Transfer
    Ngoc-Bao Nguyen
    Chandrasegaran, Keshigeyan
    Abdollahzadeh, Milad
    Cheung, Ngai-Man
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,