Evaluating Membership Inference Through Adversarial Robustness

No Thumbnail Available
File version
Author(s)
Zhang, Zhaoxi
Zhang, Leo Yu
Zheng, Xufei
Abbasi, Bilal Hussain
Hu, Shengshan
Griffith University Author(s)
Primary Supervisor
Other Supervisors
Editor(s)
Date
2022
Size
File type(s)
Location
License
Abstract

The usage of deep learning is being escalated in many applications. Due to its outstanding performance, it is being used in a variety of security and privacy-sensitive areas in addition to conventional applications. One of the key aspects of deep learning efficacy is to have abundant data. This trait leads to the usage of data which can be highly sensitive and private, which in turn causes wariness with regard to deep learning in the general public. Membership inference attacks are considered lethal as they can be used to figure out whether a piece of data belongs to the training dataset or not. This can be problematic with regard to leakage of training data information and its characteristics. To highlight the significance of these types of attacks, we propose an enhanced methodology for membership inference attacks based on adversarial robustness, by adjusting the directions of adversarial perturbations through label smoothing under a white-box setting. We evaluate our proposed method on three datasets: Fashion-MNIST, CIFAR-10 and CIFAR-100. Our experimental results reveal that the performance of our method surpasses that of the existing adversarial robustness-based method when attacking normally trained models. Additionally, through comparing our technique with the state-of-the-art metric-based membership inference methods, our proposed method also shows better performance when attacking adversarially trained models. The code for reproducing the results of this work is available at https://github.com/plll4zzx/Evaluating-Membership-Inference-Through-Adversarial-Robustness.

Journal Title

The Computer Journal

Conference Title
Book Title
Edition
Volume

65

Issue

11

Thesis Type
Degree Program
School
Publisher link
Patent number
Funder(s)
Grant identifier(s)
Rights Statement
Rights Statement
Item Access Status
Note
Access the data
Related item(s)
Subject

Information and computing sciences

Science & Technology

Technology

Computer Science, Hardware & Architecture

Computer Science, Information Systems

Computer Science, Software Engineering

Persistent link to this record
Citation

Zhang, Z; Zhang, LY; Zheng, X; Abbasi, BH; Hu, S, Evaluating Membership Inference Through Adversarial Robustness, The Computer Journal, 2022, 65 (11), pp. 2969-2978

Collections