arXiv:2410.05159cs.CVcs.CR2024-10被引 5

首个系统性评估模型反演攻击与防御的基准框架

MIBench: A Comprehensive Framework for Benchmarking Model Inversion Attack and Defense

  • 构建可扩展的模块化工具箱,集成19种主流攻防方法
  • 涵盖9项标准化评估协议,支持多场景对比分析
  • 适合隐私安全研究者评估防御方案有效性

模型反演(MI)攻击旨在利用目标模型的输出信息重构敏感训练数据,引发深度神经网络隐私漏洞的严重关切。然而,随着MI攻击的快速演进,缺乏统一标准的评估基准、可复现的实现方式及量化指标,已成为阻碍方法比较和防御效果可靠评估的重大挑战。为此,我们构建了首个实用的基准框架MIBench,用于系统评估模型反演攻击与防御。该框架基于可扩展、可复现的模块化工具箱,目前已集成19种前沿攻击与防御方法,并包含9项标准化评估协议。基于此,我们从多个维度开展全面评估,系统比较不同方法在目标分辨率、模型预测能力、防御性能及对抗鲁棒性等场景下的表现。

原文摘要 · Abstract (English)

Model Inversion (MI) attacks aim at leveraging the output information of target models to reconstruct privacy-sensitive training data, raising critical concerns regarding the privacy vulnerabilities of Deep Neural Networks (DNNs). Unfortunately, in tandem with the rapid evolution of MI attacks, the absence of a comprehensive benchmark with standardized metrics and reproducible implementations has emerged as a formidable challenge. This deficiency has hindered objective comparison of methodological advancements and reliable assessment of defense efficacy. To address this critical gap, we build the first practical benchmark named MIBench for systematic evaluation of model inversion attacks and defenses. This benchmark bases on an extensible and reproducible modular-based toolbox which currently integrates a total of 19 state-of-the-art attack and defense methods and encompasses 9 standardized evaluation protocols. Capitalizing on this foundation, we conduct extensive evaluation from multiple perspectives to holistically compare and analyze various methods across different scenarios, such as the impact of target resolution, model predictive power, defense performance and adversarial robustness.

模型反演隐私安全基准测试防御评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。