Do Backdoors Assist Membership Inference Attacks?

被引:0
作者
Goto, Yumeki [1 ]
Ashizawa, Nami [2 ]
Shibahara, Toshiki [2 ]
Yanai, Naoto [1 ]
机构
[1] Osaka Univ, I-5 Yamadaoka,Suita Shi, Osaka 5650871, Japan
[2] NTT Social Informat Labs, 3-9-11 Midori Cho,Musashino Shi, Tokyo 1808585, Japan
来源
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, PT II, SECURECOMM 2023 | 2025年 / 568卷
关键词
Backdoor-assisted membership inference attack; backdoor attack; poisoning attack; membership inference attack;
D O I
10.1007/978-3-031-64954-7_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
When an adversary provides poison samples to a machine learning model, privacy leakage, such as membership inference attacks that infer whether a sample was included in the training of the model, becomes effective by moving the sample to an outlier. However, the attacks can be detected because inference accuracy deteriorates due to poison samples. In this paper, we discuss a backdoor-assisted membership inference attack, a novel membership inference attack based on backdoors that return the adversary's expected output for a triggered sample. We found three key insights through experiments with an academic benchmark dataset. We first demonstrate that the backdoor-assisted membership inference attack is unsuccessful when backdoors are trivially used. Second, when we analyzed latent representations to understand the unsuccessful results, we found that backdoor attacks make any clean sample an inlier in contrast to poisoning attacks which make it an outlier. Finally, our promising results also show that backdoor-assisted membership inference attacks may still be possible only when backdoors whose triggers are imperceptible are used in some specific setting.
引用
收藏
页码:251 / 265
页数:15
相关论文
共 50 条
  • [31] SocInf: Membership Inference Attacks on Social Media Health Data With Machine Learning
    Liu, Gaoyang
    Wang, Chen
    Peng, Kai
    Huang, Haojun
    Li, Yutong
    Cheng, Wenqing
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2019, 6 (05) : 907 - 921
  • [32] Membership Inference Attacks Against Machine Learning Models via Prediction Sensitivity
    Liu, Lan
    Wang, Yi
    Liu, Gaoyang
    Peng, Kai
    Wang, Chen
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2341 - 2347
  • [33] BAN-MPR: Defending against Membership Inference Attacks with Born Again Networks and Membership Privacy Regularization
    Liu, Yiqing
    Yu, Juan
    Han, Jianmin
    2022 INTERNATIONAL CONFERENCE ON COMPUTERS AND ARTIFICIAL INTELLIGENCE TECHNOLOGIES, CAIT, 2022, : 9 - 15
  • [34] Efficient Membership Inference Attacks against Federated Learning via Bias Differences
    Zhang, Liwei
    Li, Linghui
    Li, Xiaoyong
    Cai, Binsi
    Gao, Yali
    Dou, Ruobin
    Chen, Luying
    PROCEEDINGS OF THE 26TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2023, 2023, : 222 - 235
  • [35] FD-Leaks: Membership Inference Attacks Against Federated Distillation Learning
    Yang, Zilu
    Zhao, Yanchao
    Zhang, Jiale
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 364 - 378
  • [36] Deep Neural Network Quantization Framework for Effective Defense against Membership Inference Attacks
    Famili, Azadeh
    Lao, Yingjie
    SENSORS, 2023, 23 (18)
  • [37] Semi-Leak: Membership Inference Attacks Against Semi-supervised Learning
    He, Xinlei
    Liu, Hongbin
    Gong, Neil Zhenqiang
    Zhang, Yang
    COMPUTER VISION, ECCV 2022, PT XXXI, 2022, 13691 : 365 - 381
  • [38] Label-only membership inference attacks on machine unlearning without dependence of posteriors
    Lu, Zhaobo
    Liang, Hai
    Zhao, Minghao
    Lv, Qingzhe
    Liang, Tiancai
    Wang, Yilei
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (11) : 9424 - 9441
  • [39] Stand-in Model Protection: Synthetic defense for membership inference and model inversion attacks
    Chen, Huajie
    Zhu, Tianqing
    Ji, Shouling
    Zhou, Wanlei
    KNOWLEDGE-BASED SYSTEMS, 2025, 316
  • [40] An Optimal Knowledge Distillation for Formulating an Effective Defense Model Against Membership Inference Attacks
    Thi Thanh Thuy Pham
    Doan, Huong-Giang
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (05) : 1399 - 1409