Membership Leakage in Label-Only Exposures
Zheng Li and Yang Zhang CISPA Helmholtz Center for Information Security
Abstract
Machine learning (ML) has been widely adopted in various privacy-critical applications, e.g., face recognition and medical image analysis. However, recent research has shown that ML models are vulnerable to attacks against their training data. Membership inference is one major attack in this domain: Given a data sample and model, an adversary aims to determine whether the sample is part of the model’s training set. Existing membership inference attacks leverage the confidence scores returned by the model as their inputs (score-based attacks). However, these attacks can be easily mitigated if the model only exposes the predicted label, i.e., the final model decision.
原文 arXiv:2007.15528;中英对照 + 大白话阅读 https://aha.fim.ai/paper/2007.15528v3