arXiv:2410.07632cs.LGcs.CR2024-10被引 4

揭示浅层神经网络在高维场景下的可证明隐私漏洞。

Provable Privacy Attacks on Trained Shallow Neural Networks

  • 利用两层ReLU网络的隐式偏差理论设计攻击
  • 高维正交环境下可高概率判断数据是否训练过
  • 适用于研究模型隐私与对抗样本的学者

我们研究了训练好的两层ReLU神经网络在两种隐私攻击下的可证明漏洞:成员推理和数据重构。在高维、近乎正交的设定下,我们证明了利用神经网络的隐式偏差理论,可以以高概率确定某一点是否出现在训练集中;在单变量设定下,可构造一个有限集合,其中至少包含常数比例的训练点。据我们所知,这是首次在隐式偏差驱动的设置中展示可证明的隐私脆弱性。

原文摘要 · Abstract (English)

We study what provable privacy attacks can be shown for trained 2-layer ReLU neural networks, focusing on two types of attacks: membership inference and data reconstruction. We prove that theoretical results on the implicit bias of 2-layer neural networks can be used to provably identify with high probability whether a given point was used in the training set in a high-dimensional, nearly orthogonal setting, and can also be used to construct a finite set of which at least a constant fraction are training points in a univariate setting. To the best of our knowledge, our work is the first to show provable vulnerabilities in this implicit-bias-driven setting.

隐私攻击神经网络深度学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。