Demystifying Membership Inference Attacks in Machine Learning as a Service
Stacey Truex Ling Liu Mehmet Emre Gursoy Lei Yu Wenqi Wei Thanks: S.Truex, L. Liu, M.E. Gursoy, L. Yu, and W. Wei are with the School of Computer Science, Georgia Institute of Technology, Atlanta, GA, 30332. Email: {staceytruex, memregursoy, leiyu, Thanks: Manuscript received X; revised Y.
Abstract
Membership inference attacks seek to infer membership of individual training instances of a model to which an adversary has black-box access through a machine learning-as-a-service API. In providing an in-depth characterization of membership privacy risks against machine learning models, this paper presents a comprehensive study towards demystifying membership inference attacks from two complimentary perspectives. First, we provide a generalized formulation of the development of a black-box membership inference attack model. Second, we characterize the importance of model choice on model vulnerability through a systematic evaluation of a variety of machine learning models and model combinations using multiple datasets. Through formal analysis and empirical evidence from extensive experimentation, we characterize under what conditions a model may be vulnerable to such black-box membership inference attacks. We show that membership inference vulnerability is data-driven and corresponding attack models are largely transferable. Though different model types display different vulnerabilities to membership inference, so do different datasets. Our empirical results additionally show that
原文 arXiv:1807.09173;中英对照 + 大白话阅读 https://aha.fim.ai/paper/1807.09173v2