Against Membership Inference Attack: Pruning is All You Need
arXiv:2008.13578
Abstract
The large model size, high computational operations, and vulnerability against membership inference attack (MIA) have impeded deep learning or deep neural networks (DNNs) popularity, especially on mobile devices. To address the challenge, we envision that the weight pruning technique will help DNNs against MIA while reducing model storage and computational operation. In this work, we propose a pruning algorithm, and we show that the proposed algorithm can find a subnetwork that can prevent privacy leakage from MIA and achieves competitive accuracy with the original DNNs. We also verify our theoretical insights with experiments. Our experimental results illustrate that the attack accuracy using model compression is up to 13.6% and 10% lower than that of the baseline and Min-Max game, accordingly.
Machine Learning (cs.LG); Cryptography and Security (cs.CR); Machine Learning (stat.ML)
References in corpus (7)
- MobileNetV2: Inverted Residuals and Linear Bottlenecks
- The Lottery Ticket Hypothesis: Finding Sparse, Trainable Neural Networks
- A Systematic DNN Weight Pruning Framework using Alternating Direction Method of Multipliers
- Learning Structured Sparsity in Deep Neural Networks
- Deconstructing Lottery Tickets: Zeros, Signs, and the Supermask
- What is the State of Neural Network Pruning?
- Machine Learning with Membership Privacy using Adversarial Regularization