Membership Privacy Protection for Image Translation Models via Adversarial Knowledge Distillation

03/10/2022
by   Saeed Ranjbar Alvar, et al.
0

Image-to-image translation models are shown to be vulnerable to the Membership Inference Attack (MIA), in which the adversary's goal is to identify whether a sample is used to train the model or not. With daily increasing applications based on image-to-image translation models, it is crucial to protect the privacy of these models against MIAs. We propose adversarial knowledge distillation (AKD) as a defense method against MIAs for image-to-image translation models. The proposed method protects the privacy of the training samples by improving the generalizability of the model. We conduct experiments on the image-to-image translation models and show that AKD achieves the state-of-the-art utility-privacy tradeoff by reducing the attack performance up to 38.9 model at the cost of a slight drop in the quality of the generated output images. The experimental results also indicate that the models trained by AKD generalize better than the regular training models. Furthermore, compared with existing defense methods, the results show that at the same privacy protection level, image translation models trained by AKD generate outputs with higher quality; while at the same quality of outputs, AKD enhances the privacy protection over 30

READ FULL TEXT

page 1

page 7

research
05/25/2022

Region-aware Knowledge Distillation for Efficient Image-to-Image Translation

Recent progress in image-to-image translation has witnessed the success ...
research
11/02/2021

Knowledge Cross-Distillation for Membership Privacy

A membership inference attack (MIA) poses privacy risks on the training ...
research
11/24/2022

CycleGANWM: A CycleGAN watermarking method for ownership verification

Due to the proliferation and widespread use of deep neural networks (DNN...
research
04/14/2023

Delta Denoising Score

We introduce Delta Denoising Score (DDS), a novel scoring function for t...
research
03/21/2021

Self adversarial attack as an augmentation method for immunohistochemical stainings

It has been shown that unpaired image-to-image translation methods const...
research
10/06/2021

Attack as the Best Defense: Nullifying Image-to-image Translation GANs via Limit-aware Adversarial Attack

With the successful creation of high-quality image-to-image (Img2Img) tr...
research
04/27/2020

Improving Endoscopic Decision Support Systems by Translating Between Imaging Modalities

Novel imaging technologies raise many questions concerning the adaptatio...

Please sign up or login with your details

Forgot password? Click here to reset