Comprehensive Privacy Analysis of Deep Learning Passive and Active White-box Inference Attacks against Centralized and Federated Learning

被引:850
|
作者
Nasr, Milad [1 ]
Shokri, Reza [2 ]
Houmansadr, Amir [1 ]
机构
[1] Univ Massachusetts, Amherst, MA 01003 USA
[2] Natl Univ Singapore, Singapore, Singapore
来源
2019 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2019) | 2019年
关键词
D O I
10.1109/SP.2019.00065
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Deep neural networks are susceptible to various inference attacks as they remember information about their training data. We design white-box inference attacks to perform a comprehensive privacy analysis of deep learning models. We measure the privacy leakage through parameters of fully trained models as well as the parameter updates of models during training. We design inference algorithms for both centralized and federated learning, with respect to passive and active inference attackers, and assuming different adversary prior knowledge. We evaluate our novel white-box membership inference attacks against deep learning algorithms to trace their training data records. We show that a straightforward extension of the known black-box attacks to the white-box setting (through analyzing the outputs of activation functions) is ineffective. We therefore design new algorithms tailored to the white-box setting by exploiting the privacy vulnerabilities of the stochastic gradient descent algorithm, which is the algorithm used to train deep neural networks. We investigate the reasons why deep learning models may leak information about their training data. We then show that even well-generalized models are significantly susceptible to white-box membership inference attacks, by analyzing state-of-the-art pre-trained and publicly available models for the CIFAR dataset. We also show how adversarial participants, in the federated learning setting, can successfully run active membership inference attacks against other participants, even when the global model achieves high prediction accuracies.
引用
收藏
页码:739 / 753
页数:15
相关论文
共 50 条
  • [21] Enhancing Deep Learning Model Privacy Against Membership Inference Attacks Using Privacy-Preserving Oversampling
    Subhasish Ghosh
    Amit Kr Mandal
    Agostino Cortesi
    SN Computer Science, 6 (4)
  • [22] White-box inference attack: compromising the security of deep learning-based COVID-19 diagnosis systems
    Sheikh B.U.H.
    Zafar A.
    International Journal of Information Technology, 2024, 16 (3) : 1475 - 1483
  • [23] A Verifiable Privacy-Preserving Federated Learning Framework Against Collusion Attacks
    Chen, Yange
    He, Suyu
    Wang, Baocang
    Feng, Zhanshen
    Zhu, Guanghui
    Tian, Zhihong
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2025, 24 (05) : 3918 - 3934
  • [24] DefendFL: A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks
    Liu, Jiao
    Li, Xinghua
    Liu, Ximeng
    Zhang, Haiyan
    Miao, Yinbin
    Deng, Robert H.
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024,
  • [25] Active Membership Inference Attack under Local Differential Privacy in Federated Learning
    Nguyen, Truc
    Lai, Phung
    Tran, Khang
    Phan, NhatHai
    Thai, My T.
    INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 206, 2023, 206
  • [26] FLSG: A Novel Defense Strategy Against Inference Attacks in Vertical Federated Learning
    Fan, Kai
    Hong, Jingtao
    Li, Wenjie
    Zhao, Xingwen
    Li, Hui
    Yang, Yintang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (02) : 1816 - 1826
  • [27] Efficient Membership Inference Attacks against Federated Learning via Bias Differences
    Zhang, Liwei
    Li, Linghui
    Li, Xiaoyong
    Cai, Binsi
    Gao, Yali
    Dou, Ruobin
    Chen, Luying
    PROCEEDINGS OF THE 26TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2023, 2023, : 222 - 235
  • [28] FD-Leaks: Membership Inference Attacks Against Federated Distillation Learning
    Yang, Zilu
    Zhao, Yanchao
    Zhang, Jiale
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 364 - 378
  • [29] Defending against Membership Inference Attacks in Federated learning via Adversarial Example
    Xie, Yuanyuan
    Chen, Bing
    Zhang, Jiale
    Wu, Di
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 153 - 160
  • [30] Leveraging deep learning-assisted attacks against image obfuscation via federated learning
    Tekli J.
    Al Bouna B.
    Tekli G.
    Couturier R.
    Charbel A.
    Neural Computing and Applications, 2024, 36 (25) : 15667 - 15684