Black-Box Based Limited Query Membership Inference Attack

被引:4
作者
Zhang, Yu [1 ]
Zhou, Huaping [1 ]
Wang, Pengyan [1 ]
Yang, Gaoming [1 ]
机构
[1] Anhui Univ Sci & Technol, Sch Comp Sci & Engn, Huainan 232001, Peoples R China
关键词
Data models; Training; Adaptation models; Training data; Predictive models; Generative adversarial networks; Machine learning; Membership inference attack; generative adversarial network; black-box attack; information leak;
D O I
10.1109/ACCESS.2022.3175824
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Conventional membership inference attacks usually require a large number of queries of the target model when training shadow models, and this task becomes extremely difficult when the number of queries is limited. Aiming at the problem of insufficient training data for shadow models due to the limited number of queries, we propose a membership inference attack method based on generative adversarial networks (GAN). First, we use generative adversarial networks to augment the samples obtained by a small number of queries to expand the training data of the model; Secondly, we use the improved CNN to obtain shadow models that have a higher degree of fitting on different target model structures; Finally, we evaluate the accuracy of the proposed algorithm on XgBoost, Logistic, and neural network models using public datasets MNIST and CIFAR10 in a black-box setting, and the results show that our model has an average attack accuracy of 62% and 83%, respectively. It can be seen that, compared with the existing research methods, our model can obtain better attack effects under the condition of significantly reducing the number of queries, which shows the feasibility of our proposed method in membership inference attacks.
引用
收藏
页码:55459 / 55468
页数:10
相关论文
共 50 条
  • [31] Demystifying the Membership Inference Attack
    Irolla, Paul
    Chatel, Gregory
    [J]. 2019 12TH CMI CONFERENCE ON CYBERSECURITY AND PRIVACY (CMI), 2019, : 1 - 7
  • [32] Uncertainty-Based Rejection Wrappers for Black-Box Classifiers
    Mena, Jose
    Pujol, Oriol
    Vitria, Jordi
    [J]. IEEE ACCESS, 2020, 8 : 101721 - 101746
  • [33] An Optimized Black-Box Adversarial Simulator Attack Based on Meta-Learning
    Chen, Zhiyu
    Ding, Jianyu
    Wu, Fei
    Zhang, Chi
    Sun, Yiming
    Sun, Jing
    Liu, Shangdong
    Ji, Yimu
    [J]. ENTROPY, 2022, 24 (10)
  • [34] An Evolutionary-Based Black-Box Attack to Deep Neural Network Classifiers
    Zhou, Yutian
    Tan, Yu-an
    Zhang, Quanxin
    Kuang, Xiaohui
    Han, Yahong
    Hu, Jingjing
    [J]. MOBILE NETWORKS & APPLICATIONS, 2021, 26 (04) : 1616 - 1629
  • [35] Black-box Adversarial Attack Method Based on Evolution Strategy and Attention Mechanism
    Huang L.-F.
    Zhuang W.-Z.
    Liao Y.-X.
    Liu N.
    [J]. Ruan Jian Xue Bao/Journal of Software, 2021, 32 (11): : 3512 - 3529
  • [36] An Evolutionary-Based Black-Box Attack to Deep Neural Network Classifiers
    Yutian Zhou
    Yu-an Tan
    Quanxin Zhang
    Xiaohui Kuang
    Yahong Han
    Jingjing Hu
    [J]. Mobile Networks and Applications, 2021, 26 : 1616 - 1629
  • [37] PISA: Pixel skipping-based attentional black-box adversarial attack
    Wang, Jie
    Yin, Zhaoxia
    Jiang, Jing
    Tang, Jin
    Luo, Bin
    [J]. COMPUTERS & SECURITY, 2022, 123
  • [38] TranFuzz: An Ensemble Black-Box Attack Framework Based on Domain Adaptation and Fuzzing
    Li, Hao
    Guo, Shanqing
    Tang, Peng
    Hu, Chengyu
    Chen, Zhenxiang
    [J]. INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2021), PT I, 2021, 12918 : 260 - 275
  • [39] Detection Tolerant Black-Box Adversarial Attack Against Automatic Modulation Classification With Deep Learning
    Qi, Peihan
    Jiang, Tao
    Wang, Lizhan
    Yuan, Xu
    Li, Zan
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2022, 71 (02) : 674 - 686
  • [40] An Adversarial Network-based Multi-model Black-box Attack
    Lin, Bin
    Chen, Jixin
    Zhang, Zhihong
    Lai, Yanlin
    Wu, Xinlong
    Tian, Lulu
    Cheng, Wangchi
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2021, 30 (02) : 641 - 649