好模型更难被攻击,增强泛化能大幅降低成员推理攻击成功率。
Generalization and Membership Inference Attack a Practical Perspective

- 用数据增强和早停提升模型泛化能力
- 攻击成功率最高可下降100倍
- 适合关注模型安全性的研究人员
随着新的评估指标和攻击方法出现,有必要重新审视关于成员推理攻击(MIA)成功率与模型泛化能力之间关系的既有假设。本文通过实证研究,考察了数据增强和早停等技术对模型泛化的影响及其对MIA成功率的作用。实验在超过1000个模型上进行,结果表明,采用先进泛化技术可使攻击性能显著下降,最多可达100倍;结合多种方法还能在训练中引入随机性,进一步削弱攻击效果。研究验证了泛化能力与MIA表现之间的直接关联。
原文摘要 · Abstract (English)
With the emergence of new evaluation metrics and attack methodologies for Membership Inference Attacks (MIA), it becomes essential to reevaluate previously accepted assumptions. In this paper, we revisit the longstanding debate regarding the correlation between MIA success rates and model generalization using an empirical approach. We focused on employing augmentation techniques and early stopping to enhance model generalization and examined their impact on MIA success rates. We found that utilizing advanced generalization techniques can significantly decrease attack performance, potentially by up to 100 times. Moreover, combining these methods not only improves model generalization but also reduces attack effectiveness by introducing randomness during training. Additionally, our study confirmed the direct impact of generalization on MIA performance through an analysis of over 1K models in a controlled environment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。