ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models

06/04/2018
by   Ahmed Salem, et al.
2

Machine learning (ML) has become a core component of many real-world applications and training data is a key factor that drives current progress. This huge success has led Internet companies to deploy machine learning as a service (MLaaS). Recently, the first membership inference attack has shown that extraction of information on the training set is possible in such MLaaS settings, which has severe security and privacy implications. However, the early demonstrations of the feasibility of such attacks have many assumptions on the adversary such as using multiple so-called shadow models, knowledge of the target model structure and having a dataset from the same distribution as the target model's training data. We relax all 3 key assumptions, thereby showing that such attacks are very broadly applicable at low cost and thereby pose a more severe risk than previously thought. We present the most comprehensive study so far on this emerging and developing threat using eight diverse datasets which show the viability of the proposed attacks across domains. In addition, we propose the first effective defense mechanisms against such broader class of membership inference attacks that maintain a high level of utility of the ML model.

READ FULL TEXT

page 5

page 8

page 9

page 10

page 12

research
09/10/2020

Privacy Analysis of Deep Learning in the Wild: Membership Inference Attacks against Transfer Learning

While being deployed in many critical applications as core components, m...
research
06/06/2018

Killing Three Birds with one Gaussian Process: Analyzing Attack Vectors on Classification

The wide usage of Machine Learning (ML) has lead to research on the atta...
research
02/04/2021

ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models

Inference attacks against Machine Learning (ML) models allow adversaries...
research
08/01/2018

MLCapsule: Guarded Offline Deployment of Machine Learning as a Service

With the widespread use of machine learning (ML) techniques, ML as a ser...
research
09/11/2023

Privacy Side Channels in Machine Learning Systems

Most current approaches for protecting privacy in machine learning (ML) ...
research
09/29/2018

Statistical Inference Attack Against PHY-layer Key Extraction and Countermeasures

The formal theoretical analysis on channel correlations in both real ind...
research
12/02/2022

Membership Inference Attacks Against Semantic Segmentation Models

Membership inference attacks aim to infer whether a data record has been...

Please sign up or login with your details

Forgot password? Click here to reset