EAR: An Enhanced Adversarial Regularization Approach against Membership Inference Attacks

被引:2
|
作者
Hu, Hongsheng [1 ]
Salcic, Zoran [1 ]
Dobbie, Gillian [2 ]
Chen, Yi [3 ]
Zhang, Xuyun [4 ]
机构
[1] Univ Auckland, Dept ECE, Auckland, New Zealand
[2] Univ Auckland, Sch Comp Sci, Auckland, New Zealand
[3] Southwest Jiaotong Univ, Sch Informat Sci & Technol, Chengdu, Peoples R China
[4] Macquarie Univ, Dept Comp, Sydney, NSW, Australia
来源
2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN) | 2021年
关键词
Data privacy; Membership inference attacks; Adversarial regularization; Machine learning;
D O I
10.1109/IJCNN52387.2021.9534381
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Membership inference attacks on a machine learning model aim to determine whether a given data record is a member of the training set. They pose severe privacy risks to individuals, e.g., identifying an individual's participation in a hospital's health analytic training set reveals that this individual was once a patient in that hospital. Adversarial regularization (AR) is one of the state-of-the-art defense methods that mitigate such attacks while preserving a model's prediction accuracy. AR adds membership inference attacks as a new regularization term to the target model during the training process. It is an adversarial training algorithm that is trained on a defended model which is essentially the same as training the generator of generative adversarial networks (GANs). We observe that many GAN variants are able to generate higher quality samples and offer more stability during the training phase than GANs. However, whether these GAN variants are available to improve the effectiveness of AR has not been investigated. In this paper, we propose an enhanced adversarial regularization (EAR) method based on Least Square GANs (LSGANs). The new EAR surpasses the existing AR in offering more powerful defensive ability while preserving the same prediction accuracy of the protected classifiers. We systematically evaluate EAR on five datasets with different target classifiers under four different attack methods and compare it with four other defense methods. We experimentally show that our new method performs the best among other defense methods.
引用
收藏
页数:8
相关论文
共 50 条
  • [41] Resilience of GANs against Adversarial Attacks
    Rudayskyy, Kyrylo
    Miri, Ali
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 390 - 397
  • [42] Comparative Analysis of Membership Inference Attacks in Federated and Centralized Learning
    Abbasi Tadi, Ali
    Dayal, Saroj
    Alhadidi, Dima
    Mohammed, Noman
    INFORMATION, 2023, 14 (11)
  • [43] Approach to Detecting Attacks against Machine Learning Systems with a Generative Adversarial Network
    Kotenko, I. V.
    Saenko, I. B.
    Lauta, O. S.
    Vasilev, N. A.
    Sadovnikov, V. E.
    PATTERN RECOGNITION AND IMAGE ANALYSIS, 2024, 34 (03) : 589 - 596
  • [44] A Robust Malware Detection Approach for Android System against Adversarial Example Attacks
    Li, Wenjia
    Bala, Neha
    Ahmar, Aemun
    Tovar, Fernanda
    Battu, Arpit
    Bambarkar, Prachi
    2019 IEEE 5TH INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (CIC 2019), 2019, : 360 - 365
  • [45] Synthetic Is All You Need: Removing the Auxiliary Data Assumption for Membership Inference Attacks Against Synthetic Data
    Guepin, Florent
    Meeus, Matthieu
    Cretu, Ana-Maria
    de Montjoye, Yves-Alexandre
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, PT I, 2024, 14398 : 182 - 198
  • [46] A Defense Method Against Facial Adversarial Attacks
    Sadu, Chiranjeevi
    Das, Pradip K.
    2021 IEEE REGION 10 CONFERENCE (TENCON 2021), 2021, : 459 - 463
  • [47] Practical Membership Inference Attack Against Collaborative Inference in Industrial IoT
    Chen, Hanxiao
    Li, Hongwei
    Dong, Guishan
    Hao, Meng
    Xu, Guowen
    Huang, Xiaoming
    Liu, Zhe
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (01) : 477 - 487
  • [48] Adversarial Attacks Against IoT Identification Systems
    Kotak, Jaidip
    Elovici, Yuval
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (09) : 7868 - 7883
  • [49] Adversarial Sampling Attacks Against Phishing Detection
    Shirazi, Hossein
    Bezawada, Bruhadeshwar
    Ray, Indrakshi
    Anderson, Charles
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXIII, 2019, 11559 : 83 - 101
  • [50] Adapting Membership Inference Attacks to GNN for Graph Classification: Approaches and Implications
    Wu, Bang
    Yang, Xiangwen
    Pan, Shirui
    Yuan, Xingliang
    2021 21ST IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM 2021), 2021, : 1421 - 1426