arXiv:2412.21061cs.LG2024-12NeurIPS被引 5

黑盒数据保护可被少量未加密数据破解,新方法能高效还原隐私数据。

BridgePure: Limited Protection Leakage Can Break Black-Box Data Protection

  • 利用少量未加密数据与接口交互,生成配对样本。
  • 训练扩散模型建立原始与保护数据映射关系。
  • 可逆推任意同分布数据的原始内容,适合安全研究者关注。

可用性攻击(又称不可学习样本)是数据所有者为防止未经授权的机器学习模型有效学习而修改数据集的防御技术,同时保持数据原有功能。这催生了多种黑盒工具(如API)供用户上传个人数据并获取受保护版本。本文揭示:若少量未受保护的同分布数据可得,此类黑盒保护将被严重破坏。我们提出新的保护泄漏威胁模型:攻击者可(1)通过向黑盒系统查询少量未加密数据,轻易获取(原始,受保护)样本对;(2)训练扩散桥接模型,构建原始与受保护数据间的映射关系。该映射称为BridgePure,能有效去除任何同分布未见数据的保护。BridgePure在分类与风格模仿任务中表现出色,暴露了黑盒数据保护中的关键漏洞。建议实践者采用多层级防护措施以降低风险。

原文摘要 · Abstract (English)

Availability attacks, or unlearnable examples, are defensive techniques that allow data owners to modify their datasets in ways that prevent unauthorized machine learning models from learning effectively while maintaining the data's intended functionality. It has led to the release of popular black-box tools (e.g., APIs) for users to upload personal data and receive protected counterparts. In this work, we show that such black-box protections can be substantially compromised if a small set of unprotected in-distribution data is available. Specifically, we propose a novel threat model of protection leakage, where an adversary can (1) easily acquire (unprotected, protected) pairs by querying the black-box protections with a small unprotected dataset; and (2) train a diffusion bridge model to build a mapping between unprotected and protected data. This mapping, termed BridgePure, can effectively remove the protection from any previously unseen data within the same distribution. BridgePure demonstrates superior purification performance on classification and style mimicry tasks, exposing critical vulnerabilities in black-box data protection. We suggest that practitioners implement multi-level countermeasures to mitigate such risks.

数据保护隐私泄露扩散模型对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。