Skip to main navigation Skip to search Skip to main content

面向机器学习的成员推理攻击综述

Translated title of the contribution: Survey of Membership Inference Attacks for Machine Learning
  • Depeng Chen
  • , Xiao Liu
  • , Jie Cui*
  • , Daojing He
  • *Corresponding author for this work
  • School of Computer Science and Technology, Anhui University
  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Artificial intelligence has been integrated into all aspects of people's daily lives with the continuous development of machine learning, especially in the deep learning area. Machine learning models are deployed in various applications, enhancing the intelligence of traditional applications. However, in recent years, research has pointed out that personal data used to train machine learning models is vulnerable to the risk of privacy disclosure. Membership inference attacks (MIAs) are significant attacks against the machine learning model that threatens users' privacy. MIA aims to judge whether user data samples are used to train the target model. When the data is closely related to the individual, such as in medical, financial, and other fields, it directly interferes with the user's private information. This paper first introduces the background knowledge of membership inference attacks. Then, we classify the existing MI As according to whether the attacker has a shadow model. We also summarize the threats of MI As in different fields. Also, this paper points out the defense means against MI As. The existing defense mechanisms are classified and summarized according to the strategies for preventing model overfitting, model-based compression, and disturbance. Finally, this paper analyzes the advantages and disadvantages of the current MIAs and defense mechanisms and proposes possible research directions for future MIAs.

Translated title of the contributionSurvey of Membership Inference Attacks for Machine Learning
Original languageChinese (Traditional)
Pages (from-to)302-317
Number of pages16
JournalComputer Science
Volume50
Issue number1
DOIs
StatePublished - 15 Jan 2023
Externally publishedYes

Fingerprint

Dive into the research topics of 'Survey of Membership Inference Attacks for Machine Learning'. Together they form a unique fingerprint.

Cite this