Skip to main navigation Skip to search Skip to main content

Synthetic data for enhanced privacy: A VAE-GAN approach against membership inference attacks

  • Jian'en Yan
  • , Haihui Huang
  • , Kairan Yang
  • , Haiyan Xu*
  • , Yanling Li
  • *Corresponding author for this work
  • Faculty of Computing, Harbin Institute of Technology
  • Inner Mongolia Normal University China

Research output: Contribution to journalArticlepeer-review

Abstract

The raw data utilized in training machine learning models faces a potential threat from membership inference attacks. To mitigate this risk, employing synthetic data instead of real data is proved effective in desensitizing the information. We introduce a novel generative model, combining Variational Autoencoder and Generative Adversarial Network, to enhance privacy protection by generating synthetic data. In our approach, discrete variables are encoded by conditional generators, and sampling training is employed to ensure the distribution of synthetic data closely aligning with the real data. The modification of the model structure prompts a refinement of the loss function. We leverage Wasserstein distance with gradient penalty and SNorm to keep the stability of the model training process. Experimental results demonstrate that the efficacy of our model surpasses existing state-of-the-art models in terms of data utility metrics. Notably, in the face of membership inference attacks, the similarity from the results indicates the difficulty when distinguish the real data from synthetic data. It means our model have highlighting capabilities for the privacy protection.

Original languageEnglish
Article number112899
JournalKnowledge-Based Systems
Volume309
DOIs
StatePublished - 30 Jan 2025
Externally publishedYes

Keywords

  • Generative Adversarial Network
  • Membership privacy
  • Synthetic data
  • Tabular data
  • Variational Autoencoder

Fingerprint

Dive into the research topics of 'Synthetic data for enhanced privacy: A VAE-GAN approach against membership inference attacks'. Together they form a unique fingerprint.

Cite this