Membership Inference Defense Algorithm Based on Neural Network Model
Purposes Focusing on the issue that the machine learning model may leak the privacy of training data during training process, which could be used by membership inference attacks, and then for stealing the sensitive information of users, an Expectation Equilibrium Optimization Algorithm (EEO) based o...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Editorial Office of Journal of Taiyuan University of Technology
2023-09-01
|
Series: | Taiyuan Ligong Daxue xuebao |
Subjects: | |
Online Access: | https://tyutjournal.tyut.edu.cn/englishpaper/show-2106.html |
_version_ | 1827283454270636032 |
---|---|
author | Yanchao LYU Yuli YANG Yongle CHEN |
author_facet | Yanchao LYU Yuli YANG Yongle CHEN |
author_sort | Yanchao LYU |
collection | DOAJ |
description | Purposes Focusing on the issue that the machine learning model may leak the privacy of training data during training process, which could be used by membership inference attacks, and then for stealing the sensitive information of users, an Expectation Equilibrium Optimization Algorithm (EEO) based on neural network is proposed. Methods The algorithm adopts the strategy of adversarial training and optimization, and can be divided into two loops: the inner loop assumes a strong enough opponent, whose goal is to maximize the expectation of the attack model; The outer loop conducts defense training in a targeted manner, with the goal of maximizing the expectation of the target model. Small batch gradient descent method is used to minimize the loss value of the inner and outer loops, which not only ensures the accuracy of the model, but also reduces the reasoning ability of adversaries. Findings Three representative image data sets MNIST, FASHION, and Face were used, and EEO was applied to the optimized neural network model for membership inference attack experiments. The test accuracy of the three data sets lost 2.2%, 4.7%, and 3.7%, respectively, while the accuracy of the attack model decreased by 14.6%, 16.5%, and 13.9%, respectively, and had been close to 50%, that is, random guess. Conclusions Experimental results show that the algorithm possesses both high availability and high privacy of the model. Although inevitable privacy leakage will still exist, the trained neural network model has a strong defense effect against membership inference attacks, and the impact on the target model can be ignored. |
first_indexed | 2024-04-24T09:36:44Z |
format | Article |
id | doaj.art-a99682dcb9e7463e9179b1e70e13eff6 |
institution | Directory Open Access Journal |
issn | 1007-9432 |
language | English |
last_indexed | 2024-04-24T09:36:44Z |
publishDate | 2023-09-01 |
publisher | Editorial Office of Journal of Taiyuan University of Technology |
record_format | Article |
series | Taiyuan Ligong Daxue xuebao |
spelling | doaj.art-a99682dcb9e7463e9179b1e70e13eff62024-04-15T09:17:01ZengEditorial Office of Journal of Taiyuan University of TechnologyTaiyuan Ligong Daxue xuebao1007-94322023-09-0154576377210.16355/j.tyut.1007-9432.2023.05.0021007-9432(2023)05-0763-10Membership Inference Defense Algorithm Based on Neural Network ModelYanchao LYU0Yuli YANG1Yongle CHEN2College of Information and Computer, Taiyuan University of Technology, Taiyuan 030024, ChinaCollege of Information and Computer, Taiyuan University of Technology, Taiyuan 030024, ChinaCollege of Information and Computer, Taiyuan University of Technology, Taiyuan 030024, ChinaPurposes Focusing on the issue that the machine learning model may leak the privacy of training data during training process, which could be used by membership inference attacks, and then for stealing the sensitive information of users, an Expectation Equilibrium Optimization Algorithm (EEO) based on neural network is proposed. Methods The algorithm adopts the strategy of adversarial training and optimization, and can be divided into two loops: the inner loop assumes a strong enough opponent, whose goal is to maximize the expectation of the attack model; The outer loop conducts defense training in a targeted manner, with the goal of maximizing the expectation of the target model. Small batch gradient descent method is used to minimize the loss value of the inner and outer loops, which not only ensures the accuracy of the model, but also reduces the reasoning ability of adversaries. Findings Three representative image data sets MNIST, FASHION, and Face were used, and EEO was applied to the optimized neural network model for membership inference attack experiments. The test accuracy of the three data sets lost 2.2%, 4.7%, and 3.7%, respectively, while the accuracy of the attack model decreased by 14.6%, 16.5%, and 13.9%, respectively, and had been close to 50%, that is, random guess. Conclusions Experimental results show that the algorithm possesses both high availability and high privacy of the model. Although inevitable privacy leakage will still exist, the trained neural network model has a strong defense effect against membership inference attacks, and the impact on the target model can be ignored.https://tyutjournal.tyut.edu.cn/englishpaper/show-2106.htmlmachine learningneural network modelmembership inference attackdata securityprivacy preservingmodel reasoning |
spellingShingle | Yanchao LYU Yuli YANG Yongle CHEN Membership Inference Defense Algorithm Based on Neural Network Model Taiyuan Ligong Daxue xuebao machine learning neural network model membership inference attack data security privacy preserving model reasoning |
title | Membership Inference Defense Algorithm Based on Neural Network Model |
title_full | Membership Inference Defense Algorithm Based on Neural Network Model |
title_fullStr | Membership Inference Defense Algorithm Based on Neural Network Model |
title_full_unstemmed | Membership Inference Defense Algorithm Based on Neural Network Model |
title_short | Membership Inference Defense Algorithm Based on Neural Network Model |
title_sort | membership inference defense algorithm based on neural network model |
topic | machine learning neural network model membership inference attack data security privacy preserving model reasoning |
url | https://tyutjournal.tyut.edu.cn/englishpaper/show-2106.html |
work_keys_str_mv | AT yanchaolyu membershipinferencedefensealgorithmbasedonneuralnetworkmodel AT yuliyang membershipinferencedefensealgorithmbasedonneuralnetworkmodel AT yonglechen membershipinferencedefensealgorithmbasedonneuralnetworkmodel |