On the Difficulty of Membership Inference Attacks
Shahbaz Rezaei, Xin Liu
摘要
Recent studies propose membership inference (MI) attacks on deep models, where the goal is to infer if a sample has been used in the training process. Despite their apparent success, these studies only report accuracy, precision, and recall of the positive class (member class). Hence, the performance of these attacks have not been clearly reported on negative class (non-member class). In this paper, we show that the way the MI attack performance has been reported is often misleading because they suffer from high false positive rate or false alarm rate (FAR) that has not been reported. FAR shows how often the attack model mislabel non-training samples (non-member) as training (member) ones. The high FAR makes MI attacks fundamentally impractical, which is particularly more significant for tasks such as membership inference where the majority of samples in reality belong to the negative (non-training) class. Moreover, we show that the current MI attack models can only identify the membership of misclassified samples with mediocre accuracy at best, which only constitute a very small portion of training samples.
We analyze several new features that have not been comprehensively explored for membership inference before, including distance to the decision boundary and gradient norms, and conclude that deep models' responses are mostly similar among train and non-train samples. We conduct several experiments on image classification tasks, including MNIST, CIFAR-10, CIFAR-100, and Ima-geNet, using various model architecture, including LeNet, AlexNet, ResNet, etc. We show that the current stateof-the-art MI attacks cannot achieve high accuracy and low FAR at the same time, even when the attacker is given several advantages. The source code is available at https://github.com/shrezaei/MI-Attack. Dataset Cifar-100 Cifar-100 Cifar-100 Model AlexNet ResNet DenseNet Target Model Train Acc. 92.48% 95.80% 99.98% Target Model Test Acc. 43.87% 74.14% 82.83% Attack Acc. 82.62% 79.13% 87.74% Attack Precision 91.90% 87.3% 86.97% Attack Recall 86.92% 87.85% 98.29% Attack F1 89.23% 87.45% 92.26% Attack Bal. Acc. 74.02% 61.70% 66.65% Attack FAR 38.89% 64.45% 65.00%
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- On the Importance of Difficulty Calibration in Membership Inference AttacksLauren Watson, Chuan Guo, Graham Cormode, Alexandre SablayrollesICLR 2022 · 被引用 189 次
- Privacy for Free: How does Dataset Condensation Help Privacy?Tian Dong, Bo Zhao, Lingjuan LyuICML 2022 · 被引用 154 次
- Bag of Tricks for Training Data Extraction from Language ModelsWeichen Yu, Tianyu Pang, Qian Liu, Chao Du 等ICML 2023 · 被引用 87 次
- MI: Multi-modal Models Membership InferencePingyi Hu, Zihan Wang, Ruoxi Sun, Hu Wang 等NeurIPS 2022 · 被引用 39 次
- Attack-Aware Noise Calibration for Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon 等NeurIPS 2024 · 被引用 23 次
它引用的顶会 Paper8
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos 等USENIX Security 2019 · 被引用 1,386 次
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang 等NDSS 2019 · 被引用 1,141 次
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 被引用 586 次
- Machine Learning Models that Remember Too MuchCongzheng Song, Thomas Ristenpart, Vitaly ShmatikovCCS 2017 · 被引用 582 次
相关 Paper
- Practical Blind Membership Inference Attack via Differential ComparisonsBo Hui, Yuchen Yang, Haolin Yuan, Philippe Burlina 等NDSS 2021
- Membership Inference Attacks With False Discovery Rate ControlChenxu Zhao, Wei Qian, Aobo Chen, Mengdi HuaiICCV 2025 · 被引用 2 次
- Privacy Leaks by Adversaries: Adversarial Iterations for Membership Inference AttackJing Xue, Zhishen Sun, Haishan Ye, Luo Luo 等AAAI 2026
- How Does Data Augmentation Affect Privacy in Machine Learning?Da Yu, Huishuai Zhang, Wei Chen, Jian Yin 等AAAI 2021 · 被引用 67 次
- Imitative Membership Inference AttackYuntao Du, Yuetian Chen, Hanshen Xiao, Bruno Ribeiro 等USENIX Security 2026
