Label-Only Membership Inference Attacks

被引:0
|
作者
Choquette-Choo, Christopher A. [1 ,2 ]
Tramer, Florian [3 ]
Carlini, Nicholas [4 ]
Papernot, Nicolas [1 ,2 ]
机构
[1] Univ Toronto, Toronto, ON, Canada
[2] Vector Inst, Toronto, ON, Canada
[3] Stanford Univ, Stanford, CA 94305 USA
[4] Google, Mountain View, CA 94043 USA
基金
加拿大自然科学与工程研究理事会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Membership inference is one of the simplest privacy threats faced by machine learning models that are trained on private sensitive data. In this attack, an adversary infers whether a particular point was used to train the model, or not, by observing the model's predictions. Whereas current attack methods all require access to the model's predicted confidence score, we introduce a labelonly attack that instead evaluates the robustness of the model's predicted (hard) labels under perturbations of the input, to infer membership. Our label-only attack is not only as-effective as attacks requiring access to confidence scores, it also demonstrates that a class of defenses against membership inference, which we call "confidence masking" because they obfuscate the confidence scores to thwart attacks, are insufficient to prevent the leakage of private information. Our experiments show that training with differential privacy or strong l(2) regularization are the only current defenses that meaningfully decrease leakage of private information, even for points that are outliers of the training distribution.
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Do Backdoors Assist Membership Inference Attacks?
    Goto, Yumeki
    Ashizawa, Nami
    Shibahara, Toshiki
    Yanai, Naoto
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, PT II, SECURECOMM 2023, 2025, 568 : 251 - 265
  • [22] Membership Inference Attacks on Machine Learning: A Survey
    Hu, Hongsheng
    Salcic, Zoran
    Sun, Lichao
    Dobbie, Gillian
    Yu, Philip S.
    Zhang, Xuyun
    ACM COMPUTING SURVEYS, 2022, 54 (11S)
  • [23] Membership Inference Attacks Against the Graph Classification
    Yang, Junze
    Li, Hongwei
    Fan, Wenshu
    Zhang, Xilin
    Hao, Meng
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 6729 - 6734
  • [24] Membership Inference Attacks are Easier on Difficult Problems
    Shafran, Avital
    Peleg, Shmuel
    Hoshen, Yedid
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 14800 - 14809
  • [25] Detection of Membership Inference Attacks on GAN Models
    Ekramifard, Ala
    Amintoosi, Haleh
    Seno, Seyed Amin Hosseini
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 17 (01): : 43 - 57
  • [26] Membership Inference Attacks and Generalization: A Causal Perspective
    Baluta, Teodora
    Shen, Shiqi
    Hitarth, S.
    Tople, Shruti
    Saxena, Prateek
    PROCEEDINGS OF THE 2022 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2022, 2022, : 249 - 262
  • [27] Membership Inference Attacks and Defenses in Classification Models
    Li, Jiacheng
    Li, Ninghui
    Ribeiro, Bruno
    PROCEEDINGS OF THE ELEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '21), 2021, : 5 - 16
  • [28] Membership Inference Attacks against Diffusion Models
    Matsumoto, Tomoya
    Miura, Takayuki
    Yanai, Naoto
    2023 IEEE SECURITY AND PRIVACY WORKSHOPS, SPW, 2023, : 77 - 83
  • [29] Membership Inference Attacks From First Principles
    Carlini, Nicholas
    Chien, Steve
    Nasr, Milad
    Song, Shuang
    Terzis, Andreas
    Tramer, Florian
    43RD IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2022), 2022, : 1897 - 1914
  • [30] Enhance membership inference attacks in federated learning
    He, Xinlong
    Xu, Yang
    Zhang, Sicong
    Xu, Weida
    Yan, Jiale
    COMPUTERS & SECURITY, 2024, 136