<p>The advancements in machine learning have made a significant impact in many industries. Today, data is collected from numerous sources like medical records, personal mobile phones, and IoT devices, to name a few. However, with so much data being collected, privacy concerns have increased. Machine learning models could be fed with training data that contains sensitive information, and the leakage of such sensitive data poses a real threat to privacy. Attacks like membership inference attacks try to infer the presence of a data record in the training set. Furthermore, black-box membership inference attacks can identify a training set record by observing the differences in metrics like entropy, standard deviation, and maximum posterior probability of non-members and members of the training dataset. Several mitigation methods have been proposed but fail to maintain the target model utility while preserving privacy. This paper studies the influence of class imbalance, overfitting, and model architecture on the efficiency of metric-based black-box membership inference attacks. Then, the paper proposes a novel metric mapping technique that strengthens the immunity of the target model against metric-based black-box membership inference attacks while preserving its utility by reconstructing the output prediction vector such that the metric distributions of non-members and members become similar.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Mitigating black-box membership inference attack using metric mapping

  • Aayush Yadav,
  • Sunil Mane

摘要

The advancements in machine learning have made a significant impact in many industries. Today, data is collected from numerous sources like medical records, personal mobile phones, and IoT devices, to name a few. However, with so much data being collected, privacy concerns have increased. Machine learning models could be fed with training data that contains sensitive information, and the leakage of such sensitive data poses a real threat to privacy. Attacks like membership inference attacks try to infer the presence of a data record in the training set. Furthermore, black-box membership inference attacks can identify a training set record by observing the differences in metrics like entropy, standard deviation, and maximum posterior probability of non-members and members of the training dataset. Several mitigation methods have been proposed but fail to maintain the target model utility while preserving privacy. This paper studies the influence of class imbalance, overfitting, and model architecture on the efficiency of metric-based black-box membership inference attacks. Then, the paper proposes a novel metric mapping technique that strengthens the immunity of the target model against metric-based black-box membership inference attacks while preserving its utility by reconstructing the output prediction vector such that the metric distributions of non-members and members become similar.