arXiv:2601.15874cs.LG2026-01被引 1

揭示表格数据隐私漏洞,发现单独特征记录极易被攻破

SoK: Challenges in Tabular Membership Inference Attacks

  • 系统梳理集中式与联邦学习下的成员推断攻击方法
  • 实测表明攻击对单独特征记录有效,即使整体效果一般
  • 适合关注数据隐私与模型安全的研究者阅读

成员推断攻击(MIAs)是评估机器学习隐私性的主流方法。本文首先对集中式与联邦学习场景下的MIAs进行系统性综述与分类拓展。其次,通过多种攻击策略验证了在表格数据上攻击的有效性,包括防御机制的对比;特别关注外部对手在联邦学习中的威胁,常被忽视。研究发现,具有唯一特征的单独特征记录(single-outs)高度易受攻击。最后,探索了攻击在不同模型架构间的迁移能力。结果表明,尽管整体攻击性能普遍较差,但针对单独特征记录仍能暴露大量敏感信息。使用不同代理模型可提升攻击效果。

原文摘要 · Abstract (English)

Membership Inference Attacks (MIAs) are currently a dominant approach for evaluating privacy in machine learning applications. Despite their significance in identifying records belonging to the training dataset, several concerns remain unexplored, particularly with regard to tabular data. In this paper, first, we provide an extensive review and analysis of MIAs considering two main learning paradigms: centralized and federated learning. We extend and refine the taxonomy for both. Second, we demonstrate the efficacy of MIAs in tabular data using several attack strategies, also including defenses. Furthermore, in a federated learning scenario, we consider the threat posed by an outsider adversary, which is often neglected. Third, we demonstrate the high vulnerability of single-outs (records with a unique signature) to MIAs. Lastly, we explore how MIAs transfer across model architectures. Our results point towards a general poor performance of these attacks in tabular data which contrasts with previous state-of-the-art. Notably, even attacks with limited attack performance can still successfully expose a large portion of single-outs. Moreover, our findings suggest that using different surrogate models makes MIAs more effective.

隐私安全成员推断表格数据联邦学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。