针对医疗图像扩散模型,提出频段校准的成员推断攻击方法。
Frequency-Calibrated Membership Inference Attacks on Medical Image Diffusion Models
- 聚焦中频重建误差,避开难重构的高频和低信息量低频
- 在多个医疗数据集上超越现有攻击方法,准确率显著提升
- 适合关注医疗数据隐私泄露风险的研究者与防护设计者
扩散模型在医疗图像生成中的应用日益广泛,但也引发隐私担忧。成员推断攻击(MIA)可判断某图像是否用于训练模型,从而量化隐私风险。现有方法依赖扩散重建误差,认为成员图像的误差更低,但医疗图像存在固有难度差异,且扩散模型难以重建高频细节。为此,本文提出频率校准重建误差(FCRE)方法:通过分析逆扩散过程,仅关注中频范围内的重建误差,排除高频(难重构)与低频(信息少)区域,降低图像固有难度带来的干扰。具体计算中频重建误差,并比较重构图像与原图的结构相似性指数(SSIM)。通过阈值判断成员身份。实验在多个医疗图像数据集上验证,该方法性能优于现有MIA方法。
原文摘要 · Abstract (English)
The increasing use of diffusion models for image generation, especially in sensitive areas like medical imaging, has raised significant privacy concerns. Membership Inference Attack (MIA) has emerged as a potential approach to determine if a specific image was used to train a diffusion model, thus quantifying privacy risks. Existing MIA methods often rely on diffusion reconstruction errors, where member images are expected to have lower reconstruction errors than non-member images. However, applying these methods directly to medical images faces challenges. Reconstruction error is influenced by inherent image difficulty, and diffusion models struggle with high-frequency detail reconstruction. To address these issues, we propose a Frequency-Calibrated Reconstruction Error (FCRE) method for MIAs on medical image diffusion models. By focusing on reconstruction errors within a specific mid-frequency range and excluding both high-frequency (difficult to reconstruct) and low-frequency (less informative) regions, our frequency-selective approach mitigates the confounding factor of inherent image difficulty. Specifically, we analyze the reverse diffusion process, obtain the mid-frequency reconstruction error, and compute the structural similarity index score between the reconstructed and original images. Membership is determined by comparing this score to a threshold. Experiments on several medical image datasets demonstrate that our FCRE method outperforms existing MIA methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。