Defenses to Membership Inference Attacks: A Survey

被引:9
|
作者
Hu, Li [1 ,2 ]
Yan, Anli [1 ]
Yan, Hongyang [1 ]
Li, Jin [1 ,2 ]
Huang, Teng [1 ]
Zhang, Yingying [1 ]
Dong, Changyu [1 ]
Yang, Chunsheng [1 ]
机构
[1] Guangzhou Univ, Inst Artificial Intelligence, Guangzhou, Peoples R China
[2] Guangzhou Univ, Guangdong Prov Key Lab Blockchain Secur, Guangzhou, Peoples R China
基金
中国国家自然科学基金;
关键词
Membership inference; privacy defense; privacy attack; Machine learning; PRIVACY;
D O I
10.1145/3620667
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Machine learning (ML) has gained widespread adoption in a variety of fields, including computer vision and natural language processing. However, ML models are vulnerable to membership inference attacks (MIAs), which can infer whether access data was used in training a target model, thus compromising the privacy of training data. This has led researchers to focus on protecting the privacy of ML. To date, although there have been extensive efforts to defend against MIAs, we still lack a comprehensive understanding of the progress made in this area, which can often impede our ability to design the most effective defense strategies. In this article, we aim to fill this critical knowledge gap by providing a systematic analysis of membership inference defense. Specifically, we classify and summarize the existing membership inference defense schemes, focusing on optimization phase and objective, basic intuition, and key technology, and we discuss possible research directions of membership inference defense in the future.
引用
收藏
页数:34
相关论文
共 50 条
  • [31] TransMIA: Membership Inference Attacks Using Transfer Shadow Training
    Hidano, Seira
    Murakami, Takao
    Kawamoto, Yusuke
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [32] A Survey on Deep Learning for Website Fingerprinting Attacks and Defenses
    Liu, Peidong
    He, Longtao
    Li, Zhoujun
    IEEE ACCESS, 2023, 11 : 26033 - 26047
  • [33] Membership Inference Attacks on Aggregated Time Series with Linear Programming
    Voyez, Antonin
    Allard, Tristan
    Avoine, Gildas
    Cauchois, Pierre
    Fromont, Elisa
    Simonin, Matthieu
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 193 - 204
  • [34] A survey on anonymous voice over IP communication: attacks and defenses
    Zhang, Ge
    Fischer-Hubner, Simone
    ELECTRONIC COMMERCE RESEARCH, 2019, 19 (03) : 655 - 687
  • [35] Link Membership Inference Attacks against Unsupervised Graph Representation Learning
    Wang, Xiuling
    Wang, Wendy Hui
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 477 - 491
  • [36] Evaluating the Vulnerability of End-to-End Automatic Speech Recognition Models To Membership Inference Attacks
    Shah, Muhammad A.
    Szurley, Joseph
    Mueller, Markus
    Mouchtaris, Athanasios
    Droppo, Jasha
    INTERSPEECH 2021, 2021, : 891 - 895
  • [37] Optimizing Label-Only Membership Inference Attacks by Global Relative Decision Boundary Distances
    Xu, Jiacheng
    Hu, Jianpeng
    Yu, Chunqing
    Tan, Chengxiang
    INFORMATION SECURITY, PT I, ISC 2024, 2025, 15257 : 107 - 126
  • [38] Synthetic image learning: Preserving performance and preventing Membership Inference Attacks
    Lomurno, Eugenio
    Matteucci, Matteo
    PATTERN RECOGNITION LETTERS, 2025, 190 : 52 - 58
  • [39] EAR: An Enhanced Adversarial Regularization Approach against Membership Inference Attacks
    Hu, Hongsheng
    Salcic, Zoran
    Dobbie, Gillian
    Chen, Yi
    Zhang, Xuyun
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [40] Deep learning model inversion attacks and defenses: a comprehensive survey
    Wencheng Yang
    Song Wang
    Di Wu
    Taotao Cai
    Yanming Zhu
    Shicheng Wei
    Yiying Zhang
    Xu Yang
    Zhaohui Tang
    Yan Li
    Artificial Intelligence Review, 58 (8)