LOGAN: Membership Inference Attacks Against Generative Models
arXiv:1705.07663
Abstract
Generative models estimate the underlying distribution of a dataset to generate realistic samples according to that distribution. In this paper, we present the first membership inference attacks against generative models: given a data point, the adversary determines whether or not it was used to train the model. Our attacks leverage Generative Adversarial Networks (GANs), which combine a discriminative and a generative model, to detect overfitting and recognize inputs that were part of training datasets, using the discriminator's capacity to learn statistical differences in distributions. We present attacks based on both white-box and black-box access to the target model, against several state-of-the-art generative models, over datasets of complex representations of faces (LFW), objects (CIFAR-10), and medical images (Diabetic Retinopathy). We also discuss the sensitivity of the attacks to different training parameters, and their robustness against mitigation strategies, finding that defenses are either ineffective or lead to significantly worse performances of the generative models in terms of training stability and/or sample quality.
References in corpus (12)
- Improved Training of Wasserstein GANs
- Stealing Machine Learning Models via Prediction APIs
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural Networks
- Lossy Image Compression with Compressive Autoencoders
- Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning
- Understanding Membership Inferences on Well-Generalized Learning Models
- AttriGuard: A Practical Defense Against Attribute Inference Attacks via Adversarial Machine Learning
- Towards Demystifying Membership Inference Attacks
- Are GANs Created Equal? A Large-Scale Study
- Towards Adversarial Retinal Image Synthesis
- Machine Learning Models that Remember Too Much
- Machine Learning with Membership Privacy using Adversarial Regularization
Cited by in corpus (10)
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
- A Framework for Evaluating Gradient Leakage Attacks in Federated Learning
- Towards Demystifying Membership Inference Attacks
- Privacy-preserving Machine Learning through Data Obfuscation
- Beyond Inferring Class Representatives: User-Level Privacy Leakage From Federated Learning
- Déjà Vu: an empirical evaluation of the memorization properties of ConvNets
- Performing Co-Membership Attacks Against Deep Generative Models
- An Efficient DP-SGD Mechanism for Large Scale NLP Models
- Ten AI Stepping Stones for Cybersecurity
- DP-CGAN: Differentially Private Synthetic Data and Label Generation