arXiv:2502.06374cs.LGcs.AI2025-02中稿 · publication in the…被引 4

无需目标模型超参数即可实现高效成员推理攻击

Hyperparameters in Score-Based Membership Inference Attacks

  • 通过匹配目标与影子模型输出分布自动选择超参数
  • 新方法使攻击性能接近使用真实超参数的攻击效果
  • 适用于隐私评估场景,尤其适合无先验知识的攻击者

成员推理攻击(MIA)已成为评估机器学习模型隐私泄露的重要框架。基于得分的MIA特别依赖模型对特定输入生成的置信度分数。现有方法隐含假设攻击者掌握目标模型的超参数,用于训练影子模型。本文证明,在迁移学习设置下,目标超参数并非必要条件。为此,我们提出一种新方法:在攻击者无先验知识时,通过匹配目标模型与影子模型的输出分布来选择影子模型的超参数。实验表明,该方法选出的超参数可使攻击性能几乎与使用真实超参数训练的攻击无异。此外,我们研究了在差分隐私(DP)迁移学习中,使用训练数据进行超参数优化(HPO)所带来的实际隐私风险。结果未发现统计显著证据表明此类做法会增加成员推理攻击的脆弱性。

原文摘要 · Abstract (English)

Membership Inference Attacks (MIAs) have emerged as a valuable framework for evaluating privacy leakage by machine learning models. Score-based MIAs are distinguished, in particular, by their ability to exploit the confidence scores that the model generates for particular inputs. Existing score-based MIAs implicitly assume that the adversary has access to the target model's hyperparameters, which can be used to train the shadow models for the attack. In this work, we demonstrate that the knowledge of target hyperparameters is not a prerequisite for MIA in the transfer learning setting. Based on this, we propose a novel approach to select the hyperparameters for training the shadow models for MIA when the attacker has no prior knowledge about them by matching the output distributions of target and shadow models. We demonstrate that using the new approach yields hyperparameters that lead to an attack near indistinguishable in performance from an attack that uses target hyperparameters to train the shadow models. Furthermore, we study the empirical privacy risk of unaccounted use of training data for hyperparameter optimization (HPO) in differentially private (DP) transfer learning. We find no statistically significant evidence that performing HPO using training data would increase vulnerability to MIA.

成员推理隐私评估迁移学习超参数优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。