Membership Inference Defense Algorithm Based on Neural Network Model

Purposes Focusing on the issue that the machine learning model may leak the privacy of training data during training process, which could be used by membership inference attacks, and then for stealing the sensitive information of users, an Expectation Equilibrium Optimization Algorithm (EEO) based o...

Full description

Bibliographic Details
Main Authors: Yanchao LYU, Yuli YANG, Yongle CHEN
Format: Article
Language:English
Published: Editorial Office of Journal of Taiyuan University of Technology 2023-09-01
Series:Taiyuan Ligong Daxue xuebao
Subjects:
Online Access:https://tyutjournal.tyut.edu.cn/englishpaper/show-2106.html
_version_ 1827283454270636032
author Yanchao LYU
Yuli YANG
Yongle CHEN
author_facet Yanchao LYU
Yuli YANG
Yongle CHEN
author_sort Yanchao LYU
collection DOAJ
description Purposes Focusing on the issue that the machine learning model may leak the privacy of training data during training process, which could be used by membership inference attacks, and then for stealing the sensitive information of users, an Expectation Equilibrium Optimization Algorithm (EEO) based on neural network is proposed. Methods The algorithm adopts the strategy of adversarial training and optimization, and can be divided into two loops: the inner loop assumes a strong enough opponent, whose goal is to maximize the expectation of the attack model; The outer loop conducts defense training in a targeted manner, with the goal of maximizing the expectation of the target model. Small batch gradient descent method is used to minimize the loss value of the inner and outer loops, which not only ensures the accuracy of the model, but also reduces the reasoning ability of adversaries. Findings Three representative image data sets MNIST, FASHION, and Face were used, and EEO was applied to the optimized neural network model for membership inference attack experiments. The test accuracy of the three data sets lost 2.2%, 4.7%, and 3.7%, respectively, while the accuracy of the attack model decreased by 14.6%, 16.5%, and 13.9%, respectively, and had been close to 50%, that is, random guess. Conclusions Experimental results show that the algorithm possesses both high availability and high privacy of the model. Although inevitable privacy leakage will still exist, the trained neural network model has a strong defense effect against membership inference attacks, and the impact on the target model can be ignored.
first_indexed 2024-04-24T09:36:44Z
format Article
id doaj.art-a99682dcb9e7463e9179b1e70e13eff6
institution Directory Open Access Journal
issn 1007-9432
language English
last_indexed 2024-04-24T09:36:44Z
publishDate 2023-09-01
publisher Editorial Office of Journal of Taiyuan University of Technology
record_format Article
series Taiyuan Ligong Daxue xuebao
spelling doaj.art-a99682dcb9e7463e9179b1e70e13eff62024-04-15T09:17:01ZengEditorial Office of Journal of Taiyuan University of TechnologyTaiyuan Ligong Daxue xuebao1007-94322023-09-0154576377210.16355/j.tyut.1007-9432.2023.05.0021007-9432(2023)05-0763-10Membership Inference Defense Algorithm Based on Neural Network ModelYanchao LYU0Yuli YANG1Yongle CHEN2College of Information and Computer, Taiyuan University of Technology, Taiyuan 030024, ChinaCollege of Information and Computer, Taiyuan University of Technology, Taiyuan 030024, ChinaCollege of Information and Computer, Taiyuan University of Technology, Taiyuan 030024, ChinaPurposes Focusing on the issue that the machine learning model may leak the privacy of training data during training process, which could be used by membership inference attacks, and then for stealing the sensitive information of users, an Expectation Equilibrium Optimization Algorithm (EEO) based on neural network is proposed. Methods The algorithm adopts the strategy of adversarial training and optimization, and can be divided into two loops: the inner loop assumes a strong enough opponent, whose goal is to maximize the expectation of the attack model; The outer loop conducts defense training in a targeted manner, with the goal of maximizing the expectation of the target model. Small batch gradient descent method is used to minimize the loss value of the inner and outer loops, which not only ensures the accuracy of the model, but also reduces the reasoning ability of adversaries. Findings Three representative image data sets MNIST, FASHION, and Face were used, and EEO was applied to the optimized neural network model for membership inference attack experiments. The test accuracy of the three data sets lost 2.2%, 4.7%, and 3.7%, respectively, while the accuracy of the attack model decreased by 14.6%, 16.5%, and 13.9%, respectively, and had been close to 50%, that is, random guess. Conclusions Experimental results show that the algorithm possesses both high availability and high privacy of the model. Although inevitable privacy leakage will still exist, the trained neural network model has a strong defense effect against membership inference attacks, and the impact on the target model can be ignored.https://tyutjournal.tyut.edu.cn/englishpaper/show-2106.htmlmachine learningneural network modelmembership inference attackdata securityprivacy preservingmodel reasoning
spellingShingle Yanchao LYU
Yuli YANG
Yongle CHEN
Membership Inference Defense Algorithm Based on Neural Network Model
Taiyuan Ligong Daxue xuebao
machine learning
neural network model
membership inference attack
data security
privacy preserving
model reasoning
title Membership Inference Defense Algorithm Based on Neural Network Model
title_full Membership Inference Defense Algorithm Based on Neural Network Model
title_fullStr Membership Inference Defense Algorithm Based on Neural Network Model
title_full_unstemmed Membership Inference Defense Algorithm Based on Neural Network Model
title_short Membership Inference Defense Algorithm Based on Neural Network Model
title_sort membership inference defense algorithm based on neural network model
topic machine learning
neural network model
membership inference attack
data security
privacy preserving
model reasoning
url https://tyutjournal.tyut.edu.cn/englishpaper/show-2106.html
work_keys_str_mv AT yanchaolyu membershipinferencedefensealgorithmbasedonneuralnetworkmodel
AT yuliyang membershipinferencedefensealgorithmbasedonneuralnetworkmodel
AT yonglechen membershipinferencedefensealgorithmbasedonneuralnetworkmodel