On the Privacy Risks of Cell-Based NAS Architectures
arXiv:2209.01688 · doi:10.1145/3548606.3560619
Abstract
Existing studies on neural architecture search (NAS) mainly focus on efficiently and effectively searching for network architectures with better performance. Little progress has been made to systematically understand if the NAS-searched architectures are robust to privacy attacks while abundant work has already shown that human-designed architectures are prone to privacy attacks. In this paper, we fill this gap and systematically measure the privacy risks of NAS architectures. Leveraging the insights from our measurement study, we further explore the cell patterns of cell-based NAS architectures and evaluate how the cell patterns affect the privacy risks of NAS-searched architectures. Through extensive experiments, we shed light on how to design robust NAS architectures against privacy attacks, and also offer a general methodology to understand the hidden correlation between the NAS-searched architectures and other privacy risks.
Accepted by CCS 2022
References in corpus (12)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- Neural Architecture Search with Reinforcement Learning
- Language Models are Few-Shot Learners
- Designing Neural Network Architectures using Reinforcement Learning
- NAS-Bench-201: Extending the Scope of Reproducible Neural Architecture Search
- Neural Architecture Search on ImageNet in Four GPU Hours: A Theoretically Inspired Perspective
- Node-Level Membership Inference Attacks Against Graph Neural Networks
- Rethinking Architecture Selection in Differentiable NAS
- Neural Architecture Dilation for Adversarial Robustness
- Membership Inference Attacks Against Recommender Systems
- On Redundancy and Diversity in Cell-based Neural Architecture Search
- Rapid Neural Architecture Search by Learning to Generate Graphs from Datasets