Model Inversion Attacks Against Collaborative Inference

被引:181
作者
He, Zecheng [1 ]
Zhang, Tianwei [2 ]
Lee, Ruby B. [1 ]
机构
[1] Princeton Univ, Princeton, NJ 08544 USA
[2] Nanyang Technol Univ, Singapore, Singapore
来源
35TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSA) | 2019年
关键词
Deep Neural Network; Model Inversion Attack; Distributed Computation;
D O I
10.1145/3359789.3359824
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The prevalence of deep learning has drawn attention to the privacy protection of sensitive data. Various privacy threats have been presented, where an adversary can steal model owners' private data. Meanwhile, countermeasures have also been introduced to achieve privacy-preserving deep learning. However, most studies only focused on data privacy during training, and ignored privacy during inference. In this paper, we devise a new set of attacks to compromise the inference data privacy in collaborative deep learning systems. Specifically, when a deep neural network and the corresponding inference task are split and distributed to different participants, one malicious participant can accurately recover an arbitrary input fed into this system, even if he has no access to other participants' data or computations, or to prediction APIs to query this system. We evaluate our attacks under different settings, models and datasets, to show their effectiveness and generalization. We also study the characteristics of deep learning models that make them susceptible to such inference privacy threats. This provides insights and guidelines to develop more privacy-preserving collaborative systems and algorithms.
引用
收藏
页码:148 / 162
页数:15
相关论文
共 51 条
[1]  
[Anonymous], 2015, INT J SECURITY NETWO
[2]  
[Anonymous], IEEE INT C ADV VID S
[3]  
[Anonymous], ACM C COMP COMM SEC
[4]  
[Anonymous], 2018, ACM C COMP COMM SEC
[5]  
[Anonymous], CORR
[6]  
[Anonymous], ACM C COMP COMM
[7]  
[Anonymous], ARXIV180204889
[8]  
[Anonymous], NETWORK DISTRIBUTED
[9]  
[Anonymous], 2016, USENIX SEC S
[10]  
[Anonymous], 2014, USENIX SEC S