快速自动化发现查询系统隐私漏洞,效率比现有方法快18倍。
QueryCheetah: Fast Automated Discovery of Attribute Inference Attacks Against Query-Based Systems
- 基于启发式搜索快速生成隐私攻击策略。
- 在18倍更快的速度下发现更强的属性推断攻击。
- 适合安全评估人员和系统开发者用于风险检测。
查询系统(QBS)是共享数据的关键方式,允许分析者从私有受保护数据集中请求聚合信息。然而,确保其真正具备隐私保护能力,攻击测试至关重要。当前攻击开发与测试高度依赖人工,难以应对系统复杂性的增长。已有自动化方法虽具潜力,但计算开销极大,实用性受限。本文提出 QueryCheetah,一种高效且有效的自动化隐私攻击发现方法,应用于属性推断攻击。实验表明,该方法在发现更强攻击的同时,相比最先进的自动化方法提速18倍。此外,QueryCheetah 可帮助系统开发者全面评估不同攻击者强度及目标个体下的隐私风险,并可直接用于更复杂的查询语法及绕过临时防御机制。
原文摘要 · Abstract (English)
Query-based systems (QBSs) are one of the key approaches for sharing data. QBSs allow analysts to request aggregate information from a private protected dataset. Attacks are a crucial part of ensuring QBSs are truly privacy-preserving. The development and testing of attacks is however very labor-intensive and unable to cope with the increasing complexity of systems. Automated approaches have been shown to be promising but are currently extremely computationally intensive, limiting their applicability in practice. We here propose QueryCheetah, a fast and effective method for automated discovery of privacy attacks against QBSs. We instantiate QueryCheetah on attribute inference attacks and show it to discover stronger attacks than previous methods while being 18 times faster than the state-of-the-art automated approach. We then show how QueryCheetah allows system developers to thoroughly evaluate the privacy risk, including for various attacker strengths and target individuals. We finally show how QueryCheetah can be used out-of-the-box to find attacks in larger syntaxes and workarounds around ad-hoc defenses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。