评估生成网络流量的隐私风险,发现部分模型泄露率达100%。
Quantifying the Privacy Implications of High-Fidelity Synthetic Network Traffic
- 设计综合隐私指标,结合成员推断与数据提取攻击
- 部分模型成员识别成功率高达88%,标识符可完全还原
- 训练数据多样性与模型拟合度是影响隐私的关键因素
为应对网络流量数据稀缺与隐私问题,研究者开发了多种生成模型来合成流量。然而,合成流量并非天然具备隐私保护能力,其泄露敏感信息的程度及测量方法仍不明确。这一挑战因模型架构多样性而加剧,不同架构影响流量表征与生成方式。本文提出一套全面的合成网络流量隐私评估指标,融合标准方法如成员推断攻击(MIA)和数据提取攻击,以及网络特定标识符与属性。通过这些指标,系统评估了多种代表性生成模型的脆弱性,并分析影响攻击成功的因素。结果表明,不同模型与数据集间隐私风险差异显著:成员推断成功率在0%至88%之间,部分场景下网络标识符可被100%恢复,揭示严重隐私漏洞。进一步发现,训练数据多样性及生成模型对训练数据的拟合程度显著影响攻击效果。研究为设计与部署低隐私泄露的生成模型提供实践指导,奠定安全合成网络流量的基础。
原文摘要 · Abstract (English)
To address the scarcity and privacy concerns of network traffic data, various generative models have been developed to produce synthetic traffic. However, synthetic traffic is not inherently privacy-preserving, and the extent to which it leaks sensitive information, and how to measure such leakage, remain largely unexplored. This challenge is further compounded by the diversity of model architectures, which shape how traffic is represented and synthesized. We introduce a comprehensive set of privacy metrics for synthetic network traffic, combining standard approaches like membership inference attacks (MIA) and data extraction attacks with network-specific identifiers and attributes. Using these metrics, we systematically evaluate the vulnerability of different representative generative models and examine the factors that influence attack success. Our results reveal substantial variability in privacy risks across models and datasets. MIA success ranges from 0% to 88%, and up to 100% of network identifiers can be recovered from generated traffic, highlighting serious privacy vulnerabilities. We further identify key factors that significantly affect attack outcomes, including training data diversity and how well the generative model fits the training data. These findings provide actionable guidance for designing and deploying generative models that minimize privacy leakage, establishing a foundation for safer synthetic network traffic generation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。