Bilateral Dependency Optimization: Defending Against Model-inversion Attacks
Xiong Peng, Feng Liu, Jingfeng Zhang, Long Lan, Junjie Ye, Tongliang Liu, Bo Han
摘要
Through using only a well-trained classifier, model-inversion (MI) attacks can recover the data used for training the classifier, leading to the privacy leakage of the training data. To defend against MI attacks, previous work utilizes a unilateral dependency optimization strategy, i.e., minimizing the dependency between inputs (i.e., features) and outputs (i.e., labels) during training the classifier. However, such a minimization process conflicts with minimizing the supervised loss that aims to maximize the dependency between inputs and outputs, causing an explicit trade-off between model robustness against MI attacks and model utility on classification tasks. In this paper, we aim to minimize the dependency between the latent representations and the inputs while maximizing the dependency between latent representations and the outputs, named a bilateral dependency optimization (BiDO) strategy. In particular, we use the dependency constraints as a universally applicable regularizer in addition to commonly used losses for deep neural networks (e.g., cross-entropy), which can be instantiated with appropriate dependency criteria according to different tasks. To verify the efficacy of our strategy, we propose two implementations of BiDO, by using two different dependency measures: BiDO with constrained covariance (BiDO-COCO) and BiDO with Hilbert-Schmidt Independence Criterion (BiDO-HSIC). Experiments show that BiDO achieves the state-of-the-art defense performance for a variety of datasets, classifiers, and MI attacks while suffering a minor classification-accuracy drop compared to the well-trained classifier with no defense, which lights up a novel road to defend against MI attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Quality-Agnostic Deepfake Detection with Intra-model Collaborative LearningBinh Minh Le, Simon S. WooICCV 2023 · 被引用 50 次
- Label-Only Model Inversion Attacks via Knowledge TransferNgoc-Bao Nguyen, Keshigeyan Chandrasegaran, Milad Abdollahzadeh, Ngai-Man CheungNeurIPS 2023 · 被引用 44 次
- Be Careful What You Smooth For: Label Smoothing Can Be a Privacy Shield but Also a Catalyst for Model Inversion AttacksLukas Struppek, Dominik Hintersdorf, Kristian KerstingICLR 2024 · 被引用 26 次
- On Strengthening and Defending Graph Reconstruction Attack with Markov Chain ApproximationZhanke Zhou, Chenyu Zhou, Xuan Li, Jiangchao Yao 等ICML 2023 · 被引用 25 次
- FedInverse: Evaluating Privacy Leakage in Federated LearningDi Wu, Jun Bai, Yiliao Song, Junjun Chen 等ICLR 2024 · 被引用 22 次
它引用的顶会 Paper14
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 被引用 628 次
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li 等NeurIPS 2021 · 被引用 419 次
- Thieves on Sesame Street! Model Extraction of BERT-based APIsKalpesh Krishna, Gaurav Singh Tomar, Ankur P. Parikh, Nicolas Papernot 等ICLR 2020 · 被引用 244 次
- Learning Deep Kernels for Non-Parametric Two-Sample TestsFeng Liu, Wenkai Xu, Jie Lu, Guangquan Zhang 等ICML 2020 · 被引用 213 次
- Information Leakage in Embedding ModelsCongzheng Song, Ananth RaghunathanCCS 2020 · 被引用 200 次
相关 Paper
- Improving Robustness to Model Inversion Attacks via Mutual Information RegularizationTianhao Wang, Yuheng Zhang, Ruoxi JiaAAAI 2021 · 被引用 98 次
- Trap-MID: Trapdoor-based Defense against Model Inversion AttacksZhenTing Liu, ShangTse ChenNeurIPS 2024 · 被引用 12 次
- Model Inversion Robustness: Can Transfer Learning Help?Sy-Tuyen Ho, Koh Jun Hao, Keshigeyan Chandrasegaran, Ngoc-Bao Nguyen 等CVPR 2024
- Stealthy Shield Defense: A Conditional Mutual Information-Based Approach against Black-Box Model Inversion AttacksTianqu Zhuang, Hongyao Yu, Yixiang Qiu, Hao Fang 等ICLR 2025
- Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature FilteringHongyao Yu, Yixiang Qiu, Hao Fang, Tianqu Zhuang 等KDD 2026 · 被引用 2 次
