USENIX Security2022Top-tier venue
Are Your Sensitive Attributes Private? Novel Model Inversion Attribute Inference Attacks on Classification Models
Shagufta Mehnaz, Sayanton V. Dibbo, Ehsanul Kabir, Ninghui Li, Elisa Bertino
Abstract
Increasing use of machine learning (ML) technologies in privacy-sensitive domains such as medical diagnoses, lifestyle predictions, and business decisions highlights the need to better understand if these ML technologies are introducing leakage of sensitive and proprietary training data. In this paper, we focus on model inversion attacks where the adversary knows non-sensitive attributes about records in the training data and aims to infer the value of a sensitive attribute unknown to the adversary, using only black-box access to the target classification model. We first devise a novel confidence score-based model inversion attribute inference attack that significantly outperforms the state-of-the-art. We then introduce a label-only model inversion attack that relies only on the model's predicted labels but still matches our confidence score-based attack in terms of attack effectiveness. We also extend our attacks to the scenario where some of the other (non-sensitive) attributes of a target record are unknown to the adversary. We evaluate our attacks on two types of machine learning models, decision tree and deep neural network, trained on three real datasets. Moreover, we empirically demonstrate the disparate vulnerability of model inversion attacks, i.e., specific groups in the training dataset (grouped by gender, race, etc.) could be more vulnerable to model inversion attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0bc8dbac-6d7e-4139-b4fa-a8cd1bcb4da7Cited by top-tier papers19
- Truth Serum: Poisoning Machine Learning Models to Reveal Their SecretsFlorian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le et al.CCS 2022 · 55 citations
- No Privacy Left Outside: On the (In-)Security of TEE-Shielded DNN Partition for On-Device MLZiqi Zhang, Chen Gong, Yifeng Cai, Yuanyuan Yuan et al.S&P 2024 · 53 citations
- Are Attribute Inference Attacks Just Imputation?Bargav Jayaraman, David EvansCCS 2022 · 42 citations
- Ferrari: Federated Feature Unlearning via Optimizing Feature SensitivityHanlin Gu, WinKent Ong, Chee Seng Chan, Lixin FanNeurIPS 2024 · 29 citations
- Do SSL Models Have Déjà Vu? A Case of Unintended Memorization in Self-supervised LearningCasey Meehan, Florian Bordes, Pascal Vincent, Kamalika Chaudhuri et al.NeurIPS 2023 · 26 citations
Builds on6
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- Neural Network Inversion in Adversarial Setting via Background Knowledge AlignmentZiqi Yang, Jiyi Zhang, Ee-Chien Chang, Zhenkai LiangCCS 2019 · 257 citations
- You Are Who You Know and How You Behave: Attribute Inference Attacks via Users' Social Friends and BehaviorsNeil Zhenqiang Gong, Bin LiuUSENIX Security 2016 · 156 citations
- Joint Item Recommendation and Attribute Inference: An Adaptive Graph Convolutional Network ApproachLe Wu, Yonghui Yang, Kun Zhang, Richang Hong et al.SIGIR 2020 · 104 citations
Related papers
- Membership Leakage in Label-Only ExposuresZheng Li, Yang ZhangCCS 2021 · 185 citations
- Reinforcement Learning-Based Black-Box Model Inversion AttacksGyojin Han, Jaehyun Choi, Haeil Lee, Junmo KimCVPR 2023
- Label-Only Model Inversion Attacks via Boundary RepulsionMostafa Kahla, Si Chen, Hoang Anh Just, Ruoxi JiaCVPR 2022 · 60 citations
- Disparate Privacy Vulnerability: Targeted Attribute Inference Attacks and DefensesEhsanul Kabir, Lucas Craig, Shagufta MehnazUSENIX Security 2025
- The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural NetworksYuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang et al.CVPR 2020
