arXiv:2509.06796cs.CRcs.LG2025-09中稿 · USENIX Security Sy…被引 3

用少量模型模仿目标模型,高效实现成员推理攻击

Imitative Membership Inference Attack

  • 通过模仿训练构建少数逼近目标模型的代理模型
  • 攻击效果超越现有方法,计算成本低于5%
  • 适合研究模型隐私漏洞或评估数据泄露风险者

成员推理攻击(MIA)通过判断特定查询实例是否属于训练集,来评估机器学习模型对训练数据的泄露程度。现有最优方法需独立训练数百个影子模型,计算开销巨大。本文提出仿效式成员推理攻击(IMIA),采用创新的模仿训练技术,仅用少量受目标模型指导的仿效模型即可精确复现目标模型的推理行为。大量实验表明,IMIA在多种攻击场景下显著优于现有方法,同时计算成本不足顶尖方案的5%。

原文摘要 · Abstract (English)

A Membership Inference Attack (MIA) assesses how much a target machine learning model reveals about its training data by determining whether specific query instances were part of the training set. State-of-the-art MIAs rely on training hundreds of shadow models that are independent of the target model, leading to significant computational overhead. In this paper, we introduce Imitative Membership Inference Attack (IMIA), which employs a novel imitative training technique to strategically construct a small number of target-informed imitative models that closely replicate the target model's behavior for inference. Extensive experimental results demonstrate that IMIA substantially outperforms existing MIAs in various attack settings while only requiring less than 5% of the computational cost of state-of-the-art approaches.

成员推理模型安全隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。