ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models
Machine learning (ML) has become a core component of many real-world\napplications and training data is a key factor that drives current progress.\nThis huge success has led Internet companies to deploy machine learning as a\nservice (MLaaS). Recently, the first membership inference attack has shown that\nextraction of information on the training set is possible in such MLaaS\nsettings, which has severe security and privacy implications.\n However, the early demonstrations of the feasibility of such attacks have\nmany assumptions on the adversary, such as using multiple so-called shadow\nmodels, knowledge of the target model structure, and having a dataset from the\nsame distribution as the target model's training data. We relax all these key\nassumptions, thereby showing that such attacks are very broadly applicable at\nlow cost and thereby pose a more severe risk than previously thought. We\npresent the most comprehensive study so far on this emerging and developing\nthreat using eight diverse datasets which show the viability of the proposed\nattacks across domains.\n In addition, we propose the first effective defense mechanisms against such\nbroader class of membership inference attacks that maintain a high level of\nutility of the ML model.\n
Paper
References (59)
Scroll for more · 38 remaining