A Survey of Privacy Attacks in Machine Learning
arXiv:2007.07646 · doi:10.1145/3624010
Abstract
As machine learning becomes more widely used, the need to study its implications in security and privacy becomes more urgent. Although the body of work in privacy has been steadily growing over the past few years, research on the privacy aspects of machine learning has received less focus than the security aspects. Our contribution in this research is an analysis of more than 40 papers related to privacy attacks against machine learning that have been published during the past seven years. We propose an attack taxonomy, together with a threat model that allows the categorization of different attacks based on the adversarial knowledge, and the assets under attack. An initial exploration of the causes of privacy leaks is presented, as well as a detailed analysis of the different attacks. Finally, we present an overview of the most commonly proposed defenses and a discussion of the open problems and future directions identified during our analysis.
Edit to add DOI. Accepted in ACM Computing Surveys, please cite the journal version
References in corpus (4)
Cited by in corpus (20)
- A Comprehensive Survey on Trustworthy Graph Neural Networks: Privacy, Robustness, Fairness, and Explainability
- The Federation Strikes Back: A Survey of Federated Learning Privacy Attacks, Defenses, Applications, and Policy Landscape
- Towards Efficient Synchronous Federated Training: A Survey on System Optimization Strategies
- Machine Learning with Confidential Computing: A Systematization of Knowledge
- Differential privacy for medical deep learning: methods, tradeoffs, and deployment implications
- FedPara: Low-Rank Hadamard Product for Communication-Efficient Federated Learning
- AUTOLYCUS: Exploiting Explainable AI (XAI) for Model Extraction Attacks against Interpretable Models
- Federated learning in food research
- Robustness and Cybersecurity in the EU Artificial Intelligence Act
- Optimal Private Median Estimation under Minimal Distributional Assumptions
- Privacy Inference Attacks and Defenses in Cloud-based Deep Neural Network: A Survey
- R-GAP: Recursive Gradient Attack on Privacy
- Survey on AI Ethics: A Socio-technical Perspective
- A Comprehensive Study of Shapley Value in Data Analytics
- Omni: Automated Ensemble with Unexpected Models against Adversarial Evasion Attack
- A Human-Centered Privacy Approach (HCP) to AI
- Poisoning Attacks to Local Differential Privacy for Ranking Estimation
- Information Density Bounds for Privacy
- Short paper: Models in the dark -- Rectification and erasure under GDPR in ML supply chains
- Rethinking Client-oriented Federated Graph Learning