Black-Box Based Limited Query Membership Inference Attack

被引:4
|
作者
Zhang, Yu [1 ]
Zhou, Huaping [1 ]
Wang, Pengyan [1 ]
Yang, Gaoming [1 ]
机构
[1] Anhui Univ Sci & Technol, Sch Comp Sci & Engn, Huainan 232001, Peoples R China
关键词
Data models; Training; Adaptation models; Training data; Predictive models; Generative adversarial networks; Machine learning; Membership inference attack; generative adversarial network; black-box attack; information leak;
D O I
10.1109/ACCESS.2022.3175824
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Conventional membership inference attacks usually require a large number of queries of the target model when training shadow models, and this task becomes extremely difficult when the number of queries is limited. Aiming at the problem of insufficient training data for shadow models due to the limited number of queries, we propose a membership inference attack method based on generative adversarial networks (GAN). First, we use generative adversarial networks to augment the samples obtained by a small number of queries to expand the training data of the model; Secondly, we use the improved CNN to obtain shadow models that have a higher degree of fitting on different target model structures; Finally, we evaluate the accuracy of the proposed algorithm on XgBoost, Logistic, and neural network models using public datasets MNIST and CIFAR10 in a black-box setting, and the results show that our model has an average attack accuracy of 62% and 83%, respectively. It can be seen that, compared with the existing research methods, our model can obtain better attack effects under the condition of significantly reducing the number of queries, which shows the feasibility of our proposed method in membership inference attacks.
引用
收藏
页码:55459 / 55468
页数:10
相关论文
共 50 条
  • [31] Query-efficient black-box ensemble attack via dynamic surrogate weighting
    Hu, Cong
    He, Zhichao
    Wu, Xiaojun
    PATTERN RECOGNITION, 2025, 161
  • [32] Black-Box Adversarial Sample Attack for Query-Less Text Classification Models
    Luo, Senlin
    Cheng, Yao
    Wan, Yunwei
    Pan, Limin
    Li, Xinshuai
    Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology, 2024, 44 (12): : 1277 - 1286
  • [33] Towards Query-efficient Black-box Adversarial Attack on Text Classification Models
    Yadollahi, Mohammad Mehdi
    Lashkari, Arash Habibi
    Ghorbani, Ali A.
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [34] Black-box Coreset Variational Inference
    Manousakas, Dionysis
    Ritter, Hippolyt
    Karaletsos, Theofanis
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [35] THE BLACK-BOX QUERY COMPLEXITY OF POLYNOMIAL SUMMATION
    Juma, Ali
    Kabanets, Valentine
    Rackoff, Charles
    Shpilka, Amir
    COMPUTATIONAL COMPLEXITY, 2009, 18 (01) : 59 - 79
  • [36] The Black-Box Query Complexity of Polynomial Summation
    Ali Juma
    Valentine Kabanets
    Charles Rackoff
    Amir Shpilka
    computational complexity, 2009, 18 : 59 - 79
  • [37] SIMULATOR ATTACK plus FOR BLACK-BOX ADVERSARIAL ATTACK
    Ji, Yimu
    Ding, Jianyu
    Chen, Zhiyu
    Wu, Fei
    Zhang, Chi
    Sun, Yiming
    Sun, Jing
    Liu, Shangdong
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 636 - 640
  • [38] Black-box Bayesian inference for agent-based models
    Dyer, Joel
    Cannon, Patrick
    Farmer, J. Doyne
    Schmon, Sebastian M.
    JOURNAL OF ECONOMIC DYNAMICS & CONTROL, 2024, 161
  • [39] Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks
    Chen, Sizhe
    Huang, Zhehao
    Tao, Qinghua
    Wu, Yingwen
    Xie, Cihang
    Huang, Xiaolin
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [40] MGAAttack: Toward More Query-efficient Black-box Attack by Microbial Genetic Algorithm
    Wang, Lina
    Yang, Kang
    Wang, Wenqi
    Wang, Run
    Ye, Aoshuang
    MM '20: PROCEEDINGS OF THE 28TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, 2020, : 2229 - 2236