Comprehensive Privacy Analysis of Deep Learning Passive and Active White-box Inference Attacks against Centralized and Federated Learning

被引:852
作者
Nasr, Milad [1 ]
Shokri, Reza [2 ]
Houmansadr, Amir [1 ]
机构
[1] Univ Massachusetts, Amherst, MA 01003 USA
[2] Natl Univ Singapore, Singapore, Singapore
来源
2019 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2019) | 2019年
关键词
D O I
10.1109/SP.2019.00065
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Deep neural networks are susceptible to various inference attacks as they remember information about their training data. We design white-box inference attacks to perform a comprehensive privacy analysis of deep learning models. We measure the privacy leakage through parameters of fully trained models as well as the parameter updates of models during training. We design inference algorithms for both centralized and federated learning, with respect to passive and active inference attackers, and assuming different adversary prior knowledge. We evaluate our novel white-box membership inference attacks against deep learning algorithms to trace their training data records. We show that a straightforward extension of the known black-box attacks to the white-box setting (through analyzing the outputs of activation functions) is ineffective. We therefore design new algorithms tailored to the white-box setting by exploiting the privacy vulnerabilities of the stochastic gradient descent algorithm, which is the algorithm used to train deep neural networks. We investigate the reasons why deep learning models may leak information about their training data. We then show that even well-generalized models are significantly susceptible to white-box membership inference attacks, by analyzing state-of-the-art pre-trained and publicly available models for the CIFAR dataset. We also show how adversarial participants, in the federated learning setting, can successfully run active membership inference attacks against other participants, even when the global model achieves high prediction accuracies.
引用
收藏
页码:739 / 753
页数:15
相关论文
共 50 条
  • [31] Analysis and improvement of differential computation attacks against internally-encoded white-box implementations
    Rivain M.
    Wang J.
    IACR Transactions on Cryptographic Hardware and Embedded Systems, 2019, 2019 (02): : 225 - 255
  • [32] Sample-free white-box out-of-distribution detection for deep learning
    Begon, Jean-Michel
    Geurts, Pierre
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS, CVPRW 2021, 2021, : 3285 - 3294
  • [33] A privacy-preserving approach for detecting smishing attacks using federated deep learning
    Mohamed Abdelkarim Remmide
    Fatima Boumahdi
    Bousmaha Ilhem
    Narhimene Boustia
    International Journal of Information Technology, 2025, 17 (1) : 547 - 553
  • [34] Multi-level membership inference attacks in federated Learning based on active GAN
    Hao Sui
    Xiaobing Sun
    Jiale Zhang
    Bing Chen
    Wenjuan Li
    Neural Computing and Applications, 2023, 35 : 17013 - 17027
  • [35] Leveraging deep learning-assisted attacks against image obfuscation via federated learning
    Tekli J.
    Al Bouna B.
    Tekli G.
    Couturier R.
    Charbel A.
    Neural Computing and Applications, 2024, 36 (25) : 15667 - 15684
  • [36] Unraveling the Connections between Privacy and Certified Robustness in Federated Learning Against Poisoning Attacks
    Xie, Chulin
    Long, Yunhui
    Chen, Pin-Yu
    Li, Qinbin
    Koyejo, Sanmi
    Li, Bo
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 1511 - 1525
  • [37] A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks in Smart Grid
    Li, Xiumin
    Wen, Mi
    He, Siying
    Lu, Rongxing
    Wang, Liangliang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (09): : 16805 - 16816
  • [38] Shield Against Gradient Leakage Attacks: Adaptive Privacy-Preserving Federated Learning
    Hu, Jiahui
    Wang, Zhibo
    Shen, Yongsheng
    Lin, Bohan
    Sun, Peng
    Pang, Xiaoyi
    Liu, Jian
    Ren, Kui
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2024, 32 (02) : 1407 - 1422
  • [39] A Robust Privacy-Preserving Federated Learning Model Against Model Poisoning Attacks
    Yazdinejad, Abbas
    Dehghantanha, Ali
    Karimipour, Hadis
    Srivastava, Gautam
    Parizi, Reza M.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6693 - 6708
  • [40] Multi-level membership inference attacks in federated Learning based on active GAN
    Sui, Hao
    Sun, Xiaobing
    Zhang, Jiale
    Chen, Bing
    Li, Wenjuan
    NEURAL COMPUTING & APPLICATIONS, 2023, 35 (23) : 17013 - 17027