File Download

There are no files associated with this item.

  Links for fulltext
     (May Require Subscription)
Supplementary

Conference Paper: Membership Inference Attack in Face of Data Transformations

TitleMembership Inference Attack in Face of Data Transformations
Authors
KeywordsData Privacy
Data Transformation
Membership Inference
Issue Date2022
Citation
2022 IEEE Conference on Communications and Network Security, CNS 2022, 2022, p. 299-307 How to Cite?
AbstractMembership inference attacks (MIAs) on machine learning models, which try to infer whether a sample is in the training dataset of a target model, have been widely studied over recent years as data privacy attracts increasing attention. One unignorable problem in the current MIA threat model is that it assumes the attacker always obtains exactly the same samples as in the training set. In reality, however, the attacker is more likely to gather only a transformed version of the training samples. For instance, portraits downloadable from a social networking website usually are re-scaled and compressed, while the website owner can train models with RAW images. We believe a transformed training sample still causes privacy leakage if the transformation is semantic-preserving. Therefore, we broaden the concept of membership inference into more realistic scenarios by considering data transformations. We introduce two strategies for designing MIAs in face of data transformations: one adapts current MIAs to transformations, and the other tries to reverse the transformations approximately. We demonstrated the effectiveness of our strategies and the significance of considering data transformations by extensive evaluations of multiple datasets with several common data transformations and by comparisons with six state-of-the-art attacks. Moreover, we conduct evaluations on data-augmented and privacy-preserving models protected by three state-of-the-art defenses.
Persistent Identifierhttp://hdl.handle.net/10722/346552

 

DC FieldValueLanguage
dc.contributor.authorChen, Jiyu-
dc.contributor.authorGuo, Yiwen-
dc.contributor.authorChen, Hao-
dc.contributor.authorGong, Neil-
dc.date.accessioned2024-09-17T04:11:41Z-
dc.date.available2024-09-17T04:11:41Z-
dc.date.issued2022-
dc.identifier.citation2022 IEEE Conference on Communications and Network Security, CNS 2022, 2022, p. 299-307-
dc.identifier.urihttp://hdl.handle.net/10722/346552-
dc.description.abstractMembership inference attacks (MIAs) on machine learning models, which try to infer whether a sample is in the training dataset of a target model, have been widely studied over recent years as data privacy attracts increasing attention. One unignorable problem in the current MIA threat model is that it assumes the attacker always obtains exactly the same samples as in the training set. In reality, however, the attacker is more likely to gather only a transformed version of the training samples. For instance, portraits downloadable from a social networking website usually are re-scaled and compressed, while the website owner can train models with RAW images. We believe a transformed training sample still causes privacy leakage if the transformation is semantic-preserving. Therefore, we broaden the concept of membership inference into more realistic scenarios by considering data transformations. We introduce two strategies for designing MIAs in face of data transformations: one adapts current MIAs to transformations, and the other tries to reverse the transformations approximately. We demonstrated the effectiveness of our strategies and the significance of considering data transformations by extensive evaluations of multiple datasets with several common data transformations and by comparisons with six state-of-the-art attacks. Moreover, we conduct evaluations on data-augmented and privacy-preserving models protected by three state-of-the-art defenses.-
dc.languageeng-
dc.relation.ispartof2022 IEEE Conference on Communications and Network Security, CNS 2022-
dc.subjectData Privacy-
dc.subjectData Transformation-
dc.subjectMembership Inference-
dc.titleMembership Inference Attack in Face of Data Transformations-
dc.typeConference_Paper-
dc.description.naturelink_to_subscribed_fulltext-
dc.identifier.doi10.1109/CNS56114.2022.9947254-
dc.identifier.scopuseid_2-s2.0-85143412319-
dc.identifier.spage299-
dc.identifier.epage307-

Export via OAI-PMH Interface in XML Formats


OR


Export to Other Non-XML Formats