揭秘金融电商中机器遗忘的攻防博弈,防范数据泄露与模型篡改
Survey of Security and Data Attacks on Machine Unlearning In Financial and E-Commerce
- 分析会员推断与数据重建等隐私攻击,揭露被删数据如何被逆向还原
- 揭示未删除数据投毒、请求滥用等安全攻击,可操控或破坏遗忘机制
- 推荐差分隐私与零知识证明等防御方案,适合高风险场景的可信遗忘
本文综述了机器遗忘在金融与电子商务应用中的安全与数据攻击现状。重点探讨了会员推断攻击和数据重构攻击等隐私威胁,即攻击者试图推断或重建本应被删除的数据。此外,还研究了机器遗忘数据投毒、遗忘请求攻击及遗忘越狱攻击等安全攻击,这些攻击针对遗忘机制本身,以操纵或破坏模型。为应对这些风险,文章评估了多种防御策略,包括差分隐私、鲁棒密码学保证以及零知识证明(ZKPs),提供可验证且抗篡改的遗忘机制。这些方法对保障高风险金融与电商场景下的数据完整性和隐私至关重要,因模型受损可能导致欺诈、数据泄露和声誉损失。本文强调需持续推进安全机器遗忘的研究,并加强对抗不断演进的攻击向量的能力。
原文摘要 · Abstract (English)
This paper surveys the landscape of security and data attacks on machine unlearning, with a focus on financial and e-commerce applications. We discuss key privacy threats such as Membership Inference Attacks and Data Reconstruction Attacks, where adversaries attempt to infer or reconstruct data that should have been removed. In addition, we explore security attacks including Machine Unlearning Data Poisoning, Unlearning Request Attacks, and Machine Unlearning Jailbreak Attacks, which target the underlying mechanisms of unlearning to manipulate or corrupt the model. To mitigate these risks, various defense strategies are examined, including differential privacy, robust cryptographic guarantees, and Zero-Knowledge Proofs (ZKPs), offering verifiable and tamper-proof unlearning mechanisms. These approaches are essential for safeguarding data integrity and privacy in high-stakes financial and e-commerce contexts, where compromised models can lead to fraud, data leaks, and reputational damage. This survey highlights the need for continued research and innovation in secure machine unlearning, as well as the importance of developing strong defenses against evolving attack vectors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。