SNAP: Efficient Extraction of Private Properties with Poisoning
Harsh Chaudhari, John Abascal, Alina Oprea, Matthew Jagielski, Florian Tramèr, Jonathan R. Ullman
Abstract
Property inference attacks allow an adversary to extract global properties of the training dataset from a machine learning model. Such attacks have privacy implications for data owners sharing their datasets to train machine learning models. Several existing approaches for property inference attacks against deep neural networks have been proposed [1] –[3], but they all rely on the attacker training a large number of shadow models, which induces a large computational overhead.In this paper, we consider the setting of property inference attacks in which the attacker can poison a subset of the training dataset and query the trained target model. Motivated by our theoretical analysis of model confidences under poisoning, we design an efficient property inference attack, SNAP, which obtains higher attack success and requires lower amounts of poisoning than the state-of-the-art poisoning-based property inference attack by Mahloujifar et al. [3]. For example, on the Census dataset, SNAP achieves 34% higher success rate than [3] while being 56.5× faster. We also extend our attack to infer whether a certain property was present at all during training and estimate the exact proportion of a property of interest efficiently. We evaluate our attack on several properties of varying proportions from four datasets and demonstrate SNAP’s generality and effectiveness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bbbf89bb-3ef9-4e18-99f0-e43d9a12ca7eCited by top-tier papers16
- Inf2Guard: An Information-Theoretic Framework for Learning Privacy-Preserving Representations against Inference AttacksSayedeh Leila Noorbakhsh, Binghui Zhang, Yuan Hong, Binghui WangUSENIX Security 2024 · 17 citations
- Property Existence Inference against Generative ModelsLijin Wang, Jingjing Wang, Jie Wan, Lin Long et al.USENIX Security 2024 · 13 citations
- Quantifying Privacy Risks of Prompts in Visual Prompt LearningYixin Wu, Rui Wen, Michael Backes, Pascal Berrang et al.USENIX Security 2024 · 12 citations
- Chameleon: Increasing Label-Only Membership Leakage with Adaptive PoisoningHarsh Chaudhari, Giorgio Severi, Alina Oprea, Jonathan R. UllmanICLR 2024 · 8 citations
- Toward Efficient Inference Attacks: Shadow Model Sharing via Mixture-of-ExpertsLi Bai, Qingqing Ye, Xinwei Zhang, Sen Zhang et al.NeurIPS 2025 · 6 citations
Builds on23
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
Related papers
- Property Inference from PoisoningSaeed Mahloujifar, Esha Ghosh, Melissa ChaseS&P 2022 · 96 citations
- Can Graph Neural Networks Expose Training Data Properties? An Efficient Risk Assessment ApproachHanyang Yuan, Jiarong Xu, Renhong Huang, Mingli Song et al.NeurIPS 2024 · 3 citations
- Property Inference Attacks Against GANsJunhao Zhou, Yufei Chen, Chao Shen, Yang ZhangNDSS 2022
- Truth Serum: Poisoning Machine Learning Models to Reveal Their SecretsFlorian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le et al.CCS 2022 · 55 citations
- Group Property Inference Attacks Against Graph Neural NetworksXiuling Wang, Wendy Hui WangCCS 2022 · 31 citations
