对比多种成员推理攻击在迁移学习中的效果,帮开发者评估模型隐私风险。
Empirical Comparison of Membership Inference Attacks in Deep Transfer Learning
- 系统比较不同成员推理攻击在迁移学习中的表现
- 数据越多,基于得分的攻击效果越差;无单一攻击能覆盖所有风险
- 似然比攻击总体最优,但特定数据集下逆海森攻击更有效
随着大规模基础模型的兴起,训练范式正从零开始训练转向迁移学习。这使得在敏感应用场景中使用小规模领域特定数据集也能实现高可用性训练。成员推理攻击(MIAs)为机器学习模型的隐私泄露提供了经验估计。然而,先前对迁移学习微调模型的MIAs评估仅限于少数几种攻击方法。本文通过对比多种MIAs在迁移学习设置下的表现,帮助从业者识别最有效的隐私风险评估攻击。我们发现,基于得分的MIAs在训练数据增加时效能下降。不存在一种攻击能覆盖所有迁移学习模型的隐私风险。尽管似然比攻击(LiRA)在多数实验场景中表现最优,但在高数据量条件下,针对PatchCamelyon数据集微调的模型,逆海森攻击(IHA)更为有效。
原文摘要 · Abstract (English)
With the emergence of powerful large-scale foundation models, the training paradigm is increasingly shifting from from-scratch training to transfer learning. This enables high utility training with small, domain-specific datasets typical in sensitive applications. Membership inference attacks (MIAs) provide an empirical estimate of the privacy leakage by machine learning models. Yet, prior assessments of MIAs against models fine-tuned with transfer learning rely on a small subset of possible attacks. We address this by comparing performance of diverse MIAs in transfer learning settings to help practitioners identify the most efficient attacks for privacy risk evaluation. We find that attack efficacy decreases with the increase in training data for score-based MIAs. We find that there is no one MIA which captures all privacy risks in models trained with transfer learning. While the Likelihood Ratio Attack (LiRA) demonstrates superior performance across most experimental scenarios, the Inverse Hessian Attack (IHA) proves to be more effective against models fine-tuned on PatchCamelyon dataset in high data regime.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。