AIセキュリティポータル K Program
Subject Membership Inference Attacks in Federated Learning
Share
Abstract
Privacy attacks on Machine Learning (ML) models often focus on inferring the existence of particular data points in the training data. However, what the adversary really wants to know is if a particular individual's (subject's) data was included during training. In such scenarios, the adversary is more likely to have access to the distribution of a particular subject than actual records. Furthermore, in settings like cross-silo Federated Learning (FL), a subject's data can be embodied by multiple data records that are spread across multiple organizations. Nearly all of the existing private FL literature is dedicated to studying privacy at two granularities -- item-level (individual data records), and user-level (participating user in the federation), neither of which apply to data subjects in cross-silo FL. This insight motivates us to shift our attention from the privacy of data records to the privacy of data subjects, also known as subject-level privacy. We propose two novel black-box attacks for subject membership inference, of which one assumes access to a model after each training round. Using these attacks, we estimate subject membership inference risk on real-world data for single-party models as well as FL scenarios. We find our attacks to be extremely potent, even without access to exact training records, and using the knowledge of membership for a handful of subjects. To better understand the various factors that may influence subject privacy risk in cross-silo FL settings, we systematically generate several hundred synthetic federation configurations, varying properties of the data, model design and training, and the federation itself. Finally, we investigate the effectiveness of Differential Privacy in mitigating this threat.
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 2021.11.18
Differential privacy
C. Dwork
Published: 2006
Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, Somesh Jha
Published: 2017.9.6
Revisiting membership inference under realistic assumptions
Bargav Jayaraman, Lingxiao Wang, Katherine Knipmeyer, Quanquan Gu, David Evans
Published: 2021
Learning new words
Abhradeep Guha Thakurta, Andrew H Vyrros, Umesh S Vaishampayan, Gaurav Kapoor, Julien Freudiger, Vivek Rangarajan Sridhar, Doug Davidson
Published: 2017
Face-auditor: Data auditing in facial recognition systems
M. Chen, Z. Zhang, T. Wang, M. Backes, Y. Zhang
Published: 2023
Formalizing and Estimating Distribution Inference Risks
Anshuman Suri, David Evans
Published: 2021.9.13
Communication-Efficient Learning of Deep Networks from Decentralized Data
H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, Blaise Agüera y Arcas
Published: 2016.2.18
Advances and open problems in federated learning
Peter Kairouz, H. Brendan McMahan, Brendan Avent, Aurélien Bellet, Mehdi Bennis, Arjun Nitin Bhagoji, Kallista Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, Rafael G. L. D’Oliveira, Hubert Eichner, Salim El Rouayheb, David Evans, Josh Gardner, Zachary Garrett, Adrià Gascón, Badih Ghazi, Phillip B. Gibbons, Marco Gruteser, Zaid Harchaoui, Chaoyang He, Lie He, Zhouyuan Huo, Ben Hutchinson, Justin Hsu, Martin Jaggi, Tara Javidi, Gauri Joshi, Mikhail Khodak, Jakub Konecný, Aleksandra Korolova, Farinaz Koushanfar, Sanmi Koyejo, Tancrède Lepoint, Yang Liu, Prateek Mittal, Mehryar Mohri, Richard Nock, Ayfer Özgür, Rasmus Pagh, Hang Qi, Daniel Ramage, Ramesh Raskar, Mariana Raykova, Dawn Song, Weikang Song, Sebastian U. Stich, Ziteng Sun, Ananda Theertha Suresh, Florian Tramèr, Praneeth Vepakomma, Jianyu Wang, Li Xiong, Zheng Xu, Qiang Yang, Felix X. Yu, Han Yu, Sen Zhao
Published: 2021
Deep Learning with Differential Privacy
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, L. Zhang
Published: 2016
Learning discrete distributions: user vs item-level privacy
Y. Liu, A. T. Suresh, F. X. X. Yu, S. Kumar, M. Riley
Published: 2020
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, Adam Smith
Published: 2006
Privacy Preservation in Federated Learning: An insightful survey from the GDPR Perspective
Nguyen Truong, Kai Sun, Siyao Wang, Florian Guitton, Yike Guo
Published: 2020.11.11
Survey: Leakage and privacy at inference time
M. Jegorova, C. Kaul, C. Mayor, A. Q. O’Neil, A. Weir, R. Murray-Smith, S. A. Tsaftaris
Published: 2022
ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models
Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, Yang Zhang
Published: 2021.2.4
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, Thomas Ristenpart
Published: 2015
The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks
Yuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang, Bo Li, Dawn Song
Published: 2019.11.17
Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers
Giuseppe Ateniese, Luigi V Mancini, Angelo Spognardi, Antonio Villani, Domenico Vitali, Giovanni Felici
Published: 2015
Property inference attacks on fully connected neural networks using permutation invariant representations
K. Ganju, Q. Wang, W. Yang, C. A. Gunter, N. Borisov
Published: 2018
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 2021.11.18
ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models
Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, Michael Backes
Published: 2018.6.5
Membership inference attacks against NLP classification models
V. Shejwalkar, H. A. Inan, A. Houmansadr, R. Sim
Published: 2021
Layer-wise characterization of latent information leakage in federated learning
Fan Mo, Anastasia Borovykh, Mohammad Malekzadeh, Hamed Haddadi, Soteris Demetriou
Published: 2021
Improved gradient inversion attacks and defenses in federated learning
Jiahui Geng, Yongli Mou, Qing Li, Feifei Li, Oya Beyan, Stefan Decker, Chunming Rong
Published: 2023
Evaluating gradient inversion attacks and defenses in federated learning
Yangsibo Huang, Samyak Gupta, Zhao Song, Kai Li, Sanjeev Arora
Published: 2021
Label leakage from gradients in distributed machine learning
A. Wainakh, T. Mußig, T. Grube, M. M ¨ uhlh ¨ auser
Published: 2021
A Quantitative Metric for Privacy Leakage in Federated Learning
Y. Liu, X. Zhu, J. Wang, J. Xiao
Published: 2021
Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning
Briland Hitaj, Giuseppe Ateniese, Fernando Perez-Cruz
Published: 2017.2.24
Active membership inference attack under local differential privacy in federated learning
T. Nguyen, P. Lai, K. Tran, N. Phan, M. T. Thai
Published: 2023
Beyond Inferring Class Representatives: User-Level Privacy Leakage From Federated Learning
Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, Hairong Qi
Published: 2018.12.3
Poisoning-assisted property inference attack against federated learning
Zhibo Wang, Yuting Huang, Mengkai Song, Libing Wu, Feng Xue, Kui Ren
Published: 2022
General or specific? investigating effective privacy protection in federated learning for speech emotion recognition
C. Tan, Y. Cao, S. Li, M. Yoshikawa
Published: 2023
Demystifying membership inference attacks in machine learning as a service
S. Truex, L. Liu, M. E. Gursoy, L. Yu, W. Wei
Published: 2019
Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
Milad Nasr, Reza Shokri, Amir Houmansadr
Published: 2018.12.4
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 2021.11.18
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 2021.11.18
Generalizing to unseen domains: A survey on domain generalization
Jindong Wang, Cuiling Lan, Chang Liu, Yidong Ouyang, Tao Qin, Wang Lu, Yiqiang Chen, Wenjun Zeng, S Yu Philip
Published: 2022
Train faster, generalize better: Stability of stochastic gradient descent
Moritz Hardt, Ben Recht, Yoram Singer
Published: 2016
The mnist database of handwritten digit images for machine learning research
Li Deng
Published: 2012
Randomized response: a survey technique for eliminating evasive answer bias
Warner, S. L.
Published: 1965
Limiting privacy breaches in privacy preserving data mining
A. Evfimievski, J. Gehrke, R. Srikant
Published: 2003
Prevalence of neural collapse during the terminal phase of deep learning training
V. Papyan, X. Y. Han, D. L. Donoho
Published: 2020
Share