Enhancing Deep Learning Model Privacy Against Membership Inference Attacks Using Privacy-Preserving Oversampling

被引:0
作者
Subhasish Ghosh [1 ]
Amit Kr Mandal [1 ]
Agostino Cortesi [2 ]
机构
[1] Department of Computer Science and Engineering, SRM University AP, Andhra Pradesh, Amaravati
[2] Department of Computer Science, Ca’ Foscari University, Via Turino 155, Venice
关键词
Deep neural networks; Differential privacy; Membership inference attack; Oversampling method;
D O I
10.1007/s42979-025-03845-1
中图分类号
学科分类号
摘要
The overfitting of deep learning models trained using moderately imbalanced datasets is the main factor in increasing the success rate of membership inference attacks. While many oversampling methods have been designed to minimize the data imbalance, only a few defend the deep neural network models against membership inference attacks. We introduce the privacy preserving synthetic minority oversampling technique (PP-SMOTE), that applies privacy preservation mechanisms during data preprocessing rather than the model training phase. The PP-SMOTE oversampling method adds Laplace noise to generate the synthetic data points of minority classes by considering the L1 sensitivity of the dataset. The PP-SMOTE oversampling method demonstrates lower vulnerability to membership inference attacks than the DNN model trained on datasets oversampled by GAN and SVMSMOTE. The PP-SMOTE oversampling method helps retain more model accuracy and lower membership inference attack accuracy compared to the differential privacy mechanisms such as DP-SGD, and DP-GAN. Experimental results showcase that PP-SMOTE effectively mitigates membership inference attack accuracy to approximately below 0.60 while preserving high model accuracy in terms of AUC score approximately above 0.90. Additionally, the broader confidence score distribution achieved by the PP-SMOTE significantly enhances both model accuracy and mitigation of membership inference attacks (MIA). This is confirmed by the loss-epoch curve which shows stable convergence and minimal overfitting during training. Also, the higher variance in confidence scores complicates efforts of attackers to distinguish training data thereby reducing the risk of MIA. © The Author(s), under exclusive licence to Springer Nature Singapore Pte Ltd. 2025.
引用
收藏
相关论文
共 50 条
  • [31] Privacy-Preserving SGD on Shuffle Model
    Zhang, Lingjie
    Zhang, Hai
    JOURNAL OF MATHEMATICS, 2023, 2023
  • [32] Privacy-Preserving Publication of Deep Neural Networks
    Sei, Yuichi
    Okumura, Hiroshi
    Ohsuga, Akihiko
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 1418 - 1425
  • [33] Privacy-preserving deep learning in medical informatics: applications, challenges, and solutions
    Naresh, Vankamamidi S.
    Thamarai, M.
    Allavarpu, V. V. L. Divakar
    ARTIFICIAL INTELLIGENCE REVIEW, 2023, 56 (SUPPL 1) : 1199 - 1241
  • [34] Privacy-preserving deep learning in medical informatics: applications, challenges, and solutions
    Vankamamidi S. Naresh
    M. Thamarai
    V. V. L. Divakar Allavarpu
    Artificial Intelligence Review, 2023, 56 : 1199 - 1241
  • [35] Privacy-Preserving Personal Model Training
    Servia-Rodriguez, Sandra
    Wang, Liang
    Zhao, Jianxin R.
    Mortier, Richard
    Haddadi, Hamed
    2018 IEEE/ACM THIRD INTERNATIONAL CONFERENCE ON INTERNET-OF-THINGS DESIGN AND IMPLEMENTATION (IOTDI 2020), 2018, : 153 - 164
  • [36] Differential Privacy in Privacy-Preserving Big Data and Learning: Challenge and Opportunity
    Jiang, Honglu
    Gao, Yifeng
    Sarwar, S. M.
    GarzaPerez, Luis
    Robin, Mahmudul
    SILICON VALLEY CYBERSECURITY CONFERENCE, SVCC 2021, 2022, 1536 : 33 - 44
  • [37] Privacy-preserving Deep Learning Models for Law Big Data Feature Learning
    Yuan, Xu
    Zhang, Jianing
    Chen, Zhikui
    Gao, Jing
    Li, Peng
    IEEE 17TH INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP / IEEE 17TH INT CONF ON PERVAS INTELLIGENCE AND COMP / IEEE 5TH INT CONF ON CLOUD AND BIG DATA COMP / IEEE 4TH CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/CBDCOM/CYBERSCITECH), 2019, : 128 - 134
  • [38] BAN-MPR: Defending against Membership Inference Attacks with Born Again Networks and Membership Privacy Regularization
    Liu, Yiqing
    Yu, Juan
    Han, Jianmin
    2022 INTERNATIONAL CONFERENCE ON COMPUTERS AND ARTIFICIAL INTELLIGENCE TECHNOLOGIES, CAIT, 2022, : 9 - 15
  • [39] Privacy-preserving federated learning on lattice quantization
    Zhang, Lingjie
    Zhang, Hai
    INTERNATIONAL JOURNAL OF WAVELETS MULTIRESOLUTION AND INFORMATION PROCESSING, 2023, 21 (06)
  • [40] Achieving Consensus in Privacy-Preserving Decentralized Learning
    Xiang, Liyao
    Wang, Lingdong
    Wang, Shufan
    Li, Baochun
    2020 IEEE 40TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS), 2020, : 899 - 909