arXiv:2504.00758cs.LGstat.ML2025-04中稿 · KDD被引 2

针对差分隐私生成的合成数据,提出更高效精准的成员推理攻击

TAMIS: Tailored Membership Inference Attacks on Synthetic Data

  • 仅用合成数据恢复图模型,无需额外影子模型
  • 新攻击评分有天然阈值,准确率与现有方法相当
  • 适合研究数据隐私泄露风险的学者和安全评估人员

成员推理攻击(MIA)可实证评估机器学习算法的隐私性。本文提出TAMIS,一种针对基于图模型的差分隐私合成数据生成方法的新MIA。该攻击在近期最先进的MAMA-MIA基础上改进:首先,仅通过合成数据即可恢复生成图模型,无需依赖辅助影子模型,降低计算成本且性能更优;其次,提出更数学严谨的攻击得分,具备自然二分类阈值。实验表明,TAMIS在复现SNAKE挑战任务时,性能优于或等同于MAMA-MIA。

原文摘要 · Abstract (English)

Membership Inference Attacks (MIA) enable to empirically assess the privacy of a machine learning algorithm. In this paper, we propose TAMIS, a novel MIA against differentially-private synthetic data generation methods that rely on graphical models. This attack builds upon MAMA-MIA, a recently-published state-of-the-art method. It lowers its computational cost and requires less attacker knowledge. Our attack is the product of a two-fold improvement. First, we recover the graphical model having generated a synthetic dataset by using solely that dataset, rather than shadow-modeling over an auxiliary one. This proves less costly and more performant. Second, we introduce a more mathematically-grounded attack score, that provides a natural threshold for binary predictions. In our experiments, TAMIS achieves better or similar performance as MAMA-MIA on replicas of the SNAKE challenge.

成员推理合成数据隐私攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。