首页    期刊浏览 2025年07月25日 星期五
登录注册

文章基本信息

  • 标题:Membership Inference Attack against Differentially Private Deep Learning Model
  • 本地全文:下载
  • 作者:Md Atiqur Rahman ; Tanzila Rahman ; Robert Laganière
  • 期刊名称:Transactions on Data Privacy
  • 印刷版ISSN:1888-5063
  • 电子版ISSN:2013-1631
  • 出版年度:2018
  • 卷号:11
  • 期号:1
  • 页码:61-79
  • 出版社:IIIA-CSIC
  • 摘要:The unprecedented success of deep learning is largely dependent on the availability ofmassive amount of training data. In many cases, these data are crowd-sourced and may contain sensitiveand confidential information, therefore, pose privacy concerns. As a result, privacy-preservingdeep learning has been gaining increasing focus nowadays. One of the promising approaches forprivacy-preserving deep learning is to employ differential privacy during model training which aimsto prevent the leakage of sensitive information about the training data via the trained model. Whilethese models are considered to be immune to privacy attacks, with the advent of recent and sophisticatedattack models, it is not clear how well these models trade-off utility for privacy. In this paper,we systematically study the impact of a sophisticated machine learning based privacy attack calledthe membership inference attack against a state-of-the-art differentially private deep model. Morespecifically, given a differentially private deep model with its associated utility, we investigate howmuch we can infer about the model’s training data. Our experimental results show that differentiallyprivate deep models may keep their promise to provide privacy protection against strong adversariesby only offering poor model utility, while exhibit moderate vulnerability to the membership inferenceattack when they offer an acceptable utility. For evaluating our experiments, we use the CIFAR-10and MNIST datasets and the corresponding classification tasks.
  • 关键词:differential privacy; membership inference attack; deep learning; privacy-preserving deep;learning; differentially private deep learning
国家哲学社会科学文献中心版权所有