Survey of Membership Inference Attacks for Machine Learning

Artificial intelligence has been integrated into all aspects of people's daily lives with the continuous development of machine learning,especially in the deep learning area.Machine learning models are deployed in various applications,enhancing the intelligence of traditional applications.Howev...

Full description

Bibliographic Details
Main Author: CHEN Depeng, LIU Xiao, CUI Jie, HE Daojing
Format: Article
Language:zho
Published: Editorial office of Computer Science 2023-01-01
Series:Jisuanji kexue
Subjects:
Online Access:https://www.jsjkx.com/fileup/1002-137X/PDF/1002-137X-2023-50-1-302.pdf
_version_ 1797845109792833536
author CHEN Depeng, LIU Xiao, CUI Jie, HE Daojing
author_facet CHEN Depeng, LIU Xiao, CUI Jie, HE Daojing
author_sort CHEN Depeng, LIU Xiao, CUI Jie, HE Daojing
collection DOAJ
description Artificial intelligence has been integrated into all aspects of people's daily lives with the continuous development of machine learning,especially in the deep learning area.Machine learning models are deployed in various applications,enhancing the intelligence of traditional applications.However,in recent years,research has pointed out that personal data used to train machine learning models is vulnerable to the risk of privacy disclosure.Membership inference attacks(MIAs) are significant attacks against the machine learning model that threatens users' privacy.MIA aims to judge whether user data samples are used to train the target model.When the data is closely related to the individual,such as in medical,financial,and other fields,it directly interferes with the user's private information.This paper first introduces the background knowledge of membership inference attacks.Then,we classify the existing MIAs according to whether the attacker has a shadow model.We also summarize the threats of MIAs in different fields.Also,this paper points out the defense means against MIAs.The existing defense mechanisms are classified and summarized according to the strategies for preventing model overfitting,model-based compression,and disturbance.Finally,this paper analyzes the advantages and disadvantages of the current MIAs and defense mechanisms and proposes possible research directions for future MIAs.
first_indexed 2024-04-09T17:33:15Z
format Article
id doaj.art-199e17464e2e4f809d34eab509859704
institution Directory Open Access Journal
issn 1002-137X
language zho
last_indexed 2024-04-09T17:33:15Z
publishDate 2023-01-01
publisher Editorial office of Computer Science
record_format Article
series Jisuanji kexue
spelling doaj.art-199e17464e2e4f809d34eab5098597042023-04-18T02:33:09ZzhoEditorial office of Computer ScienceJisuanji kexue1002-137X2023-01-0150130231710.11896/jsjkx.220800227Survey of Membership Inference Attacks for Machine LearningCHEN Depeng, LIU Xiao, CUI Jie, HE Daojing01 School of Computer Science and Technology,Anhui University,Hefei 230601,China ;2 School of Computer Science and Technology,Harbin Institute of Technology(Shenzhen),Shenzhen,Guangdong 518055,ChinaArtificial intelligence has been integrated into all aspects of people's daily lives with the continuous development of machine learning,especially in the deep learning area.Machine learning models are deployed in various applications,enhancing the intelligence of traditional applications.However,in recent years,research has pointed out that personal data used to train machine learning models is vulnerable to the risk of privacy disclosure.Membership inference attacks(MIAs) are significant attacks against the machine learning model that threatens users' privacy.MIA aims to judge whether user data samples are used to train the target model.When the data is closely related to the individual,such as in medical,financial,and other fields,it directly interferes with the user's private information.This paper first introduces the background knowledge of membership inference attacks.Then,we classify the existing MIAs according to whether the attacker has a shadow model.We also summarize the threats of MIAs in different fields.Also,this paper points out the defense means against MIAs.The existing defense mechanisms are classified and summarized according to the strategies for preventing model overfitting,model-based compression,and disturbance.Finally,this paper analyzes the advantages and disadvantages of the current MIAs and defense mechanisms and proposes possible research directions for future MIAs.https://www.jsjkx.com/fileup/1002-137X/PDF/1002-137X-2023-50-1-302.pdfmachine learning|privacy-preserving|membership inference attack|defense mechanism
spellingShingle CHEN Depeng, LIU Xiao, CUI Jie, HE Daojing
Survey of Membership Inference Attacks for Machine Learning
Jisuanji kexue
machine learning|privacy-preserving|membership inference attack|defense mechanism
title Survey of Membership Inference Attacks for Machine Learning
title_full Survey of Membership Inference Attacks for Machine Learning
title_fullStr Survey of Membership Inference Attacks for Machine Learning
title_full_unstemmed Survey of Membership Inference Attacks for Machine Learning
title_short Survey of Membership Inference Attacks for Machine Learning
title_sort survey of membership inference attacks for machine learning
topic machine learning|privacy-preserving|membership inference attack|defense mechanism
url https://www.jsjkx.com/fileup/1002-137X/PDF/1002-137X-2023-50-1-302.pdf
work_keys_str_mv AT chendepengliuxiaocuijiehedaojing surveyofmembershipinferenceattacksformachinelearning