Property Inference from Poisoning
Saeed Mahloujifar, Esha Ghosh, Melissa Chase
Abstract
Property inference attacks consider an adversary who has access to a trained ML model and tries to extract some global statistics of the training data. In this work, we study property inference in scenarios where the adversary can maliciously control a part of the training data (poisoning data) with the goal of increasing the leakage. Previous works on poisoning attacks focused on trying to decrease the accuracy of models. Here, for the first time, we study poisoning attacks where the goal of the adversary is to increase the information leakage of the model. We show that poisoning attacks can boost the information leakage significantly and should be considered as a stronger threat model in sensitive applications where some of the data sources may be malicious.We theoretically prove that our attack can always succeed as long as the learning algorithm used has good generalization properties. Then we experimentally evaluate our on different datasets (Census dataset, Enron email dataset, MNIST and CelebA), properties (that are present in the training data as features, that are not present as features, and properties that are uncorrelated with the rest of the training data or classification task) and model architectures (including Resnet-18 and Resnet-50). We were able to achieve high attack accuracy with relatively low poisoning rate, namely, 2–3% poisoning in most of our experiments. We also evaluated our attacks on models trained with DP and we show that even with very small values for , the attack is still quite successful1.1Code is available at https://github.com/smahloujifar/PropertyInferenceFromPoisoning.git
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 64279520-6429-4745-bdce-3bbd93357797Cited by top-tier papers25
- Amplifying Membership Exposure via Data PoisoningYufei Chen, Chao Shen, Yun Shen, Cong Wang et al.NeurIPS 2022 · 56 citations
- Truth Serum: Poisoning Machine Learning Models to Reveal Their SecretsFlorian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le et al.CCS 2022 · 55 citations
- Inf2Guard: An Information-Theoretic Framework for Learning Privacy-Preserving Representations against Inference AttacksSayedeh Leila Noorbakhsh, Binghui Zhang, Yuan Hong, Binghui WangUSENIX Security 2024 · 17 citations
- Property Existence Inference against Generative ModelsLijin Wang, Jingjing Wang, Jie Wan, Lin Long et al.USENIX Security 2024 · 13 citations
- Quantifying Privacy Risks of Prompts in Visual Prompt LearningYixin Wu, Rui Wen, Michael Backes, Pascal Berrang et al.USENIX Security 2024 · 12 citations
Builds on12
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 628 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
Related papers
- SNAP: Efficient Extraction of Private Properties with PoisoningHarsh Chaudhari, John Abascal, Alina Oprea, Matthew Jagielski et al.S&P 2023
- Group Property Inference Attacks Against Graph Neural NetworksXiuling Wang, Wendy Hui WangCCS 2022 · 31 citations
- Are Attribute Inference Attacks Just Imputation?Bargav Jayaraman, David EvansCCS 2022 · 42 citations
- Forget to Flourish: Leveraging Machine-Unlearning on Pretrained Language Models for Privacy LeakageMd. Rafi Ur Rashid, Jing Liu, Toshiaki Koike-Akino, Ye Wang et al.AAAI 2025 · 17 citations
- Exploring the Limits of Model-Targeted Indiscriminate Data Poisoning AttacksYiwei Lu, Gautam Kamath, Yaoliang YuICML 2023 · 25 citations
