模型隐私漏洞不均等,攻击者可精准定位高风险群体
Disparate Privacy Vulnerability: Targeted Attribute Inference Attacks and Defenses
- 提出差异性推理攻击,识别数据中易受攻击的高危群体
- 实现针对特定子集的定向攻击,准确率显著高于传统方法
- 首次提出兼顾性能与安全的差异缓解方案,适合医疗金融领域
随着机器学习在医疗、金融等敏感领域的普及,训练数据中包含的隐私信息面临泄露风险。攻击者可通过查询模型的公开非敏感属性,推断其私密敏感属性,即属性推理攻击。此类攻击的危险性在于:虽整体预测效果差,但对少数脆弱群体却极为精准,形成差异性隐私漏洞。本文揭示该现象可被利用,提出新型差异推理攻击,用于识别高风险群体;进一步设计两种定向攻击变体,能精准定位并攻击脆弱数据子集,是该领域首次实现的针对性攻击,准确率远超无差别攻击。同时,首次提出一种有效且不损害模型性能的差异缓解技术,全面防范定向攻击威胁。
原文摘要 · Abstract (English)
As machine learning (ML) technologies become more prevalent in privacy-sensitive areas like healthcare and finance, eventually incorporating sensitive information in building data-driven algorithms, it is vital to scrutinize whether these data face any privacy leakage risks. One potential threat arises from an adversary querying trained models using the public, non-sensitive attributes of entities in the training data to infer their private, sensitive attributes, a technique known as the attribute inference attack. This attack is particularly deceptive because, while it may perform poorly in predicting sensitive attributes across the entire dataset, it excels at predicting the sensitive attributes of records from a few vulnerable groups, a phenomenon known as disparate vulnerability. This paper illustrates that an adversary can take advantage of this disparity to carry out a series of new attacks, showcasing a threat level beyond previous imagination. We first develop a novel inference attack called the disparity inference attack, which targets the identification of high-risk groups within the dataset. We then introduce two targeted variations of the attribute inference attack that can identify and exploit a vulnerable subset of the training data, marking the first instances of targeted attacks in this category, achieving significantly higher accuracy than untargeted versions. We are also the first to introduce a novel and effective disparity mitigation technique that simultaneously preserves model performance and prevents any risk of targeted attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。