Privacy Inference Attacks and Defenses in Cloud-based Deep Neural Network: A Survey
arXiv:2105.06300
Abstract
Deep Neural Network (DNN), one of the most powerful machine learning algorithms, is increasingly leveraged to overcome the bottleneck of effectively exploring and analyzing massive data to boost advanced scientific development. It is not a surprise that cloud computing providers offer the cloud-based DNN as an out-of-the-box service. Though there are some benefits from the cloud-based DNN, the interaction mechanism among two or multiple entities in the cloud inevitably induces new privacy risks. This survey presents the most recent findings of privacy attacks and defenses appeared in cloud-based neural network services. We systematically and thoroughly review privacy attacks and defenses in the pipeline of cloud-based DNN service, i.e., data manipulation, training, and prediction. In particular, a new theory, called cloud-based ML privacy game, is extracted from the recently published literature to provide a deep understanding of state-of-the-art research. Finally, the challenges and future work are presented to help researchers to continue to push forward the competitions between privacy attackers and defenders.
References in corpus (12)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Explaining and Harnessing Adversarial Examples
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
- Understanding deep learning requires rethinking generalization
- A Survey of Privacy Attacks in Machine Learning
- Machine Learning Based Cyber Attacks Targeting on Controlled Information: A Survey
- Entangled Watermarks as a Defense against Model Extraction
- Analyzing and Improving Representations with the Soft Nearest Neighbor Loss
- GS-WGAN: A Gradient-Sanitized Approach for Learning Differentially Private Generators
- Adversarial Neural Network Inversion via Auxiliary Knowledge Alignment
- Exploiting Excessive Invariance caused by Norm-Bounded Adversarial Robustness
- An Adversarial Regularisation for Semi-Supervised Training of Structured Output Neural Networks