arXiv:2511.04716cs.CRcs.AI2025-11被引 1

针对认知诊断模型的隐私泄露风险,提出基于用户画像的新型入侵攻击方法。

P-MIA: A Profiled-Based Membership Inference Attack on Cognitive Diagnosis Models

  • 利用可视化知识状态向量逆向还原模型内部信息
  • 在三个真实数据集上显著超越传统黑盒攻击
  • 可作为机器遗忘技术的审计工具,揭示其缺陷

认知诊断模型(CDMs)在智能教育平台中用于构建精细的学习者画像,但其训练数据涉及敏感学生信息,引发严重隐私担忧。尽管成员推断攻击(MIA)已在多个领域被研究,但针对CDMs的应用仍属空白,隐私风险未被量化。本文首次系统研究了对CDMs的MIA。提出一种新颖且现实的灰盒威胁模型,利用平台通过雷达图等可视化手段暴露的模型内部知识状态向量。实验表明,这些向量可被准确逆向重构,构成强大攻击面。基于此,我们提出基于画像的成员推断攻击(P-MIA)框架,同时利用模型最终预测概率与暴露的知识状态向量作为特征。在三个真实数据集上对主流CDMs的大量实验显示,该灰盒攻击显著优于标准黑盒基线。此外,我们展示了P-MIA作为审计工具的潜力,成功评估了机器遗忘技术的有效性并揭示其局限性。

原文摘要 · Abstract (English)

Cognitive diagnosis models (CDMs) are pivotal for creating fine-grained learner profiles in modern intelligent education platforms. However, these models are trained on sensitive student data, raising significant privacy concerns. While membership inference attacks (MIA) have been studied in various domains, their application to CDMs remains a critical research gap, leaving their privacy risks unquantified. This paper is the first to systematically investigate MIA against CDMs. We introduce a novel and realistic grey box threat model that exploits the explainability features of these platforms, where a model's internal knowledge state vectors are exposed to users through visualizations such as radar charts. We demonstrate that these vectors can be accurately reverse-engineered from such visualizations, creating a potent attack surface. Based on this threat model, we propose a profile-based MIA (P-MIA) framework that leverages both the model's final prediction probabilities and the exposed internal knowledge state vectors as features. Extensive experiments on three real-world datasets against mainstream CDMs show that our grey-box attack significantly outperforms standard black-box baselines. Furthermore, we showcase the utility of P-MIA as an auditing tool by successfully evaluating the efficacy of machine unlearning techniques and revealing their limitations.

隐私安全成员推断认知诊断灰盒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。