Enhancing Deep Learning Model Privacy Against Membership Inference Attacks Using Privacy-Preserving Oversampling

被引:0
|
作者
Subhasish Ghosh [1 ]
Amit Kr Mandal [1 ]
Agostino Cortesi [2 ]
机构
[1] SRM University AP,Department of Computer Science and Engineering
[2] Ca’ Foscari University,Department of Computer Science
关键词
Oversampling method; Deep neural networks; Membership inference attack; Differential privacy;
D O I
10.1007/s42979-025-03845-1
中图分类号
学科分类号
摘要
The overfitting of deep learning models trained using moderately imbalanced datasets is the main factor in increasing the success rate of membership inference attacks. While many oversampling methods have been designed to minimize the data imbalance, only a few defend the deep neural network models against membership inference attacks. We introduce the privacy preserving synthetic minority oversampling technique (PP-SMOTE), that applies privacy preservation mechanisms during data preprocessing rather than the model training phase. The PP-SMOTE oversampling method adds Laplace noise to generate the synthetic data points of minority classes by considering the L1 sensitivity of the dataset. The PP-SMOTE oversampling method demonstrates lower vulnerability to membership inference attacks than the DNN model trained on datasets oversampled by GAN and SVMSMOTE. The PP-SMOTE oversampling method helps retain more model accuracy and lower membership inference attack accuracy compared to the differential privacy mechanisms such as DP-SGD, and DP-GAN. Experimental results showcase that PP-SMOTE effectively mitigates membership inference attack accuracy to approximately below 0.60 while preserving high model accuracy in terms of AUC score approximately above 0.90. Additionally, the broader confidence score distribution achieved by the PP-SMOTE significantly enhances both model accuracy and mitigation of membership inference attacks (MIA). This is confirmed by the loss-epoch curve which shows stable convergence and minimal overfitting during training. Also, the higher variance in confidence scores complicates efforts of attackers to distinguish training data thereby reducing the risk of MIA.
引用
收藏
相关论文
共 50 条
  • [21] Local Model Privacy-Preserving Study for Federated Learning
    Pan, Kaiyun
    He, Daojing
    Xu, Chuan
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2021, PT I, 2021, 398 : 287 - 307
  • [22] Privacy-Preserving Machine Learning [Cryptography]
    Kerschbaum, Florian
    Lukas, Nils
    IEEE SECURITY & PRIVACY, 2023, 21 (06) : 90 - 94
  • [23] Survey on Privacy-Preserving Machine Learning
    Liu J.
    Meng X.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2020, 57 (02): : 346 - 362
  • [24] Adaptive privacy-preserving federated learning
    Liu, Xiaoyuan
    Li, Hongwei
    Xu, Guowen
    Lu, Rongxing
    He, Miao
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2020, 13 (06) : 2356 - 2366
  • [25] Privacy-Preserving Stochastic Gradual Learning
    Han, Bo
    Tsang, Ivor W.
    Xiao, Xiaokui
    Chen, Ling
    Fung, Sai-Fu
    Yu, Celina P.
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2021, 33 (08) : 3129 - 3140
  • [26] Privacy-preserving Techniques in Federated Learning
    Liu Y.-X.
    Chen H.
    Liu Y.-H.
    Li C.-P.
    Ruan Jian Xue Bao/Journal of Software, 2022, 33 (03): : 1057 - 1092
  • [27] Adaptive privacy-preserving federated learning
    Xiaoyuan Liu
    Hongwei Li
    Guowen Xu
    Rongxing Lu
    Miao He
    Peer-to-Peer Networking and Applications, 2020, 13 : 2356 - 2366
  • [28] Utility-aware and Privacy-preserving Trajectory Synthesis Model that Resists Social Relationship Privacy Attacks
    Zheng, Zhirun
    Li, Zhetao
    Li, Jie
    Jiang, Hongbo
    Li, Tong
    Guo, Bin
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2022, 13 (03)
  • [29] Differential Privacy Protection Against Membership Inference Attack on Machine Learning for Genomic Data
    Chen, Junjie
    Wang, Wendy Hui
    Shi, Xinghua
    PACIFIC SYMPOSIUM ON BICOMPUTING 2021, 2021, : 26 - 37
  • [30] Privacy-Preserving Parametric Inference: A Case for Robust Statistics
    Avella-Medina, Marco
    JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 2021, 116 (534) : 969 - 983