arXiv:2501.02182cs.LGcs.AI2025-01被引 5

动态调整混元策略,提升模型抗成员推断攻击能力。

AdaMixup: A Dynamic Defense Framework for Membership Inference Attack Mitigation

  • 训练中自适应调整混元方法,增强隐私保护
  • 多数据集实验显示攻击成功率显著降低
  • 兼顾防御效果与模型准确率,适合隐私敏感场景

成员推断攻击已成为深度学习模型训练中的重大隐私隐患,攻击者可基于模型输出推断某数据点是否属于训练集。为此,本文提出一种新型防御机制AdaMixup,通过在训练过程中动态调整混元策略,增强模型对成员推断攻击的鲁棒性。该方法不仅提升了模型的隐私保护能力,同时保持了较高的性能表现。在多个数据集上的实验结果表明,AdaMixup显著降低了成员推断攻击的风险,并在防御效率与模型准确率之间取得了良好平衡。本研究为数据隐私保护提供了有效方案,并为未来混元训练方法的发展奠定了基础。

原文摘要 · Abstract (English)

Membership inference attacks have emerged as a significant privacy concern in the training of deep learning models, where attackers can infer whether a data point was part of the training set based on the model's outputs. To address this challenge, we propose a novel defense mechanism, AdaMixup. AdaMixup employs adaptive mixup techniques to enhance the model's robustness against membership inference attacks by dynamically adjusting the mixup strategy during training. This method not only improves the model's privacy protection but also maintains high performance. Experimental results across multiple datasets demonstrate that AdaMixup significantly reduces the risk of membership inference attacks while achieving a favorable trade-off between defensive efficiency and model accuracy. This research provides an effective solution for data privacy protection and lays the groundwork for future advancements in mixup training methods.

隐私保护成员推断防御机制混元训练

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。