PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
July 1, 20240 citationsOpen Access

A Method to Facilitate Membership Inference Attacks in Deep Learning Models

View Full Paper
ZCZitao ChenKPKarthik Pattabiraman

Key Points

Key points are not available for this paper at this time.

Abstract

Modern machine learning (ML) ecosystems offer a surging number of ML frameworks and code repositories that can greatly facilitate the development of ML models. Today, even ordinary data holders who are not ML experts can apply off-the-shelf codebase to build high-performance ML models on their data, many of which are sensitive in nature (e.g., clinical records). In this work, we consider a malicious ML provider who supplies model-training code to the data holders, does not have access to the training process, and has only black-box query access to the resulting model. In this setting, we demonstrate a new form of membership inference attack that is strictly more powerful than prior art. Our attack empowers the adversary to reliably de-identify all the training samples (average >99% attack TPR@0.1% FPR), and the compromised models still maintain competitive performance as their uncorrupted counterparts (average <1% accuracy drop). Moreover, we show that the poisoned models can effectively disguise the amplified membership leakage under common membership privacy auditing, which can only be revealed by a set of secret samples known by the adversary. Overall, our study not only points to the worst-case membership privacy leakage, but also unveils a common pitfall underlying existing privacy auditing methods, which calls for future efforts to rethink the current practice of auditing membership privacy in machine learning models.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Chen et al. (2024) studied this question.

synapsesocial.com/papers/68e6229ab6db6435875b4d1dhttps://doi.org/10.48550/arxiv.2407.01919
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Towards Demystifying Membership Inference Attacks2018 · 86 citations
  2. 2Privacy Backdoors: Enhancing Membership Inference through Poisoning Pre-trained Models2024 · 1 citations
  3. 3Deeper Leakage from Gradients through Membership Inference Attack2024 · 1 citations
  4. 4Unveiling the Unseen: Exploring Whitebox Membership Inference through the Lens of Explainability2024 · 2 citations
  5. 5Membership Privacy for Machine Learning Models Through Knowledge Transfer2021 · 74 citations