新算法能精准识别时间序列模型中的数据记忆,提升隐私泄露检测能力。
A new membership inference attack that spots memorization in generative and predictive models: Loss-Based with Reference Model algorithm (LBRM)
- 用参考模型对比损失,定位被遗忘的训练数据
- 未微调时AUROC提升40%,微调后达60%
- 适用于多种时间序列插补模型,适合关注隐私安全的研究者
生成模型可能无意中记忆训练数据,带来严重隐私风险。本文针对时间序列插补模型中的记忆现象,提出基于参考模型的损失方法(LBRM)。该方法利用参考模型提升成员推断攻击的准确性,区分训练与测试数据。贡献有二:一是提出有效提取并识别记忆数据的新方法,显著提升检测精度;平均而言,未经微调时AUROC提升约40%,微调后提升约60%;二是通过在两类时间序列插补架构上进行成员推断攻击验证,证明了LBRM方法在不同场景下的鲁棒性与通用性。结果表明,该方法大幅增强了对时间序列插补模型中记忆行为的检测能力,有效应对隐私风险。
原文摘要 · Abstract (English)
Generative models can unintentionally memorize training data, posing significant privacy risks. This paper addresses the memorization phenomenon in time series imputation models, introducing the Loss-Based with Reference Model (LBRM) algorithm. The LBRM method leverages a reference model to enhance the accuracy of membership inference attacks, distinguishing between training and test data. Our contributions are twofold: first, we propose an innovative method to effectively extract and identify memorized training data, significantly improving detection accuracy. On average, without fine-tuning, the AUROC improved by approximately 40\%. With fine-tuning, the AUROC increased by approximately 60\%. Second, we validate our approach through membership inference attacks on two types of architectures designed for time series imputation, demonstrating the robustness and versatility of the LBRM approach in different contexts. These results highlight the significant enhancement in detection accuracy provided by the LBRM approach, addressing privacy risks in time series imputation models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。