基于標(biāo)簽的無數(shù)據(jù)的成員推理攻擊
網(wǎng)絡(luò)安全與數(shù)據(jù)治理 2023年第5期
楊盼盼,,張信明
(中國科學(xué)技術(shù)大學(xué)計算機科學(xué)與技術(shù)學(xué)院,安徽合肥230026)
摘要: 成員推理攻擊根據(jù)模型的預(yù)測結(jié)果推斷特定記錄是否為模型的訓(xùn)練數(shù)據(jù)成員,在隱私保護等領(lǐng)域具有重要應(yīng)用意義。現(xiàn)有的基于標(biāo)簽的無數(shù)據(jù)的成員推理攻擊方法主要利用對抗樣本技術(shù),存在查詢和計算成本較高的問題,。對此提出一種新的成員推理攻擊方法,該方法利用影子模型來減少多次攻擊的查詢代價,并提出數(shù)據(jù)篩選與優(yōu)化策略以提高攻擊模型的性能,。實驗在兩個常見的圖像數(shù)據(jù)集上進行,,結(jié)果表明該方法同時具有較高的攻擊成功率和較低的查詢成本。
中圖分類號:TP181
文獻標(biāo)識碼:A
DOI:10.19358/j.issn.2097-1788.2023.05.008
引用格式:楊盼盼,,張信明.基于標(biāo)簽的無數(shù)據(jù)的成員推理攻擊[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,,2023,42(5):44-49.
文獻標(biāo)識碼:A
DOI:10.19358/j.issn.2097-1788.2023.05.008
引用格式:楊盼盼,,張信明.基于標(biāo)簽的無數(shù)據(jù)的成員推理攻擊[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,,2023,42(5):44-49.
Label-based data-free membership inference attack
Yang Panpan,,Zhang Xinming
(School of Computer Science and Technology, University of Science and Technology of China, Hefei 230026, China)
Abstract: Membership inference attack infers whether a specific record is a training data member of a model based on the model′s prediction results, which has important application significance in the field of privacy protection. Existing labelbased datafree membership inference attack methods mainly use adversarial sample technology, which has a high query and computation cost. This paper proposed a new membership inference attack method that uses a shadow model to reduce the query cost of multiple attacks, and proposed data filtering and optimization strategies to improve the performance of the attack model. Experiments were conducted on two commonly used image datasets, and the results showed that the proposed method has both a high attack success rate and a low query cost.
Key words : membership inference attack; datafree; labelbased
0 引言
目前很多機器學(xué)習(xí)模型以服務(wù)的形式對外提供查詢接口,,返回模型的預(yù)測結(jié)果。這些模型很容易受到成員推理攻擊,。成員推理攻擊是一種針對機器學(xué)習(xí)模型的隱私攻擊,,主要目的是根據(jù)模型的預(yù)測結(jié)果,推斷特定記錄是否為模型的訓(xùn)練數(shù)據(jù)成員,。成員推理攻擊在實際應(yīng)用中具有重要的意義,,例如在隱私保護領(lǐng)域中,攻擊者可能通過成員推理攻擊來揭示個人數(shù)據(jù)是否包含在某個模型的訓(xùn)練數(shù)據(jù)中,。
本文詳細內(nèi)容請下載:http://forexkbc.com/resource/share/2000005333
作者信息:
楊盼盼,,張信明
(中國科學(xué)技術(shù)大學(xué)計算機科學(xué)與技術(shù)學(xué)院,安徽合肥230026)
此內(nèi)容為AET網(wǎng)站原創(chuàng),,未經(jīng)授權(quán)禁止轉(zhuǎn)載,。