Lune

CVPR2021Top-tier venue

On the Difficulty of Membership Inference Attacks

Shahbaz Rezaei, Xin Liu

2021Year
17Top-tier citations

Abstract

Recent studies propose membership inference (MI) attacks on deep models, where the goal is to infer if a sample has been used in the training process. Despite their apparent success, these studies only report accuracy, precision, and recall of the positive class (member class). Hence, the performance of these attacks have not been clearly reported on negative class (non-member class). In this paper, we show that the way the MI attack performance has been reported is often misleading because they suffer from high false positive rate or false alarm rate (FAR) that has not been reported. FAR shows how often the attack model mislabel non-training samples (non-member) as training (member) ones. The high FAR makes MI attacks fundamentally impractical, which is particularly more significant for tasks such as membership inference where the majority of samples in reality belong to the negative (non-training) class. Moreover, we show that the current MI attack models can only identify the membership of misclassified samples with mediocre accuracy at best, which only constitute a very small portion of training samples.

We analyze several new features that have not been comprehensively explored for membership inference before, including distance to the decision boundary and gradient norms, and conclude that deep models' responses are mostly similar among train and non-train samples. We conduct several experiments on image classification tasks, including MNIST, CIFAR-10, CIFAR-100, and Ima-geNet, using various model architecture, including LeNet, AlexNet, ResNet, etc. We show that the current stateof-the-art MI attacks cannot achieve high accuracy and low FAR at the same time, even when the attacker is given several advantages. The source code is available at https://github.com/shrezaei/MI-Attack. Dataset Cifar-100 Cifar-100 Cifar-100 Model AlexNet ResNet DenseNet Target Model Train Acc. 92.48% 95.80% 99.98% Target Model Test Acc. 43.87% 74.14% 82.83% Attack Acc. 82.62% 79.13% 87.74% Attack Precision 91.90% 87.3% 86.97% Attack Recall 86.92% 87.85% 98.29% Attack F1 89.23% 87.45% 92.26% Attack Bal. Acc. 74.02% 61.70% 66.65% Attack FAR 38.89% 64.45% 65.00%

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 8dcb9fef-4c06-4ae4-9e66-ab99261c43ce

Cited by top-tier papers17

Ask how each one uses it

Builds on8

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines