Scholay

学术搜索 · AI 审稿 · LaTeX 协作

Attribute-Based Membership Inference Attacks and Defenses on GANs

作者:Hui Sun, Tianqing Zhu, Jie Li, Shoulin Ji, Wanlei Zhou · 发表于:IEEE Transactions on Dependable and Secure Computing · 年份:2023 · DOI:10.1109/tdsc.2023.3305591 · 被引用次数:13 · 研究领域:Generative Adversarial Networks and Image Synthesis、Adversarial Robustness in Machine Learning、Digital Media Forensic Detection

With breakthroughs in high-resolution image generation, applications for disentangled generative adversarial networks (GANs) have attracted much attention. At the same time, the privacy issues associated with GAN models have been raising many concerns. Membership inference attacks (MIAs), where an adversary attempts to determine whether or not a sample has been used to train the victim model, are a major risk with GANs. In prior research, scholars have shown that successful MIAs can be mounted by leveraging overfit images. However, high-resolution images make the existing MIAs fail due to their complexity. And the nature of disentangled GANs is such that the attributes are overfitting, which means that, for an MIA to be successful, it must likely be based on overfitting attributes. Furthermore, given the empirical difficulties with obtaining independent and identically distributed (IID) candidate samples, choosing the non-trivial attributes of candidate samples as the target for exploring overfitting would be a more preferable choice. Hence, in this paper, we propose a series of attribute-based MIAs that considers both black-box and white-box settings. The attacks are performed on the generator, and the inferences are derived by overfitting the non-trivial attributes. Additionally, we put forward a novel perspective on model generalization and a possible defense by evaluating the overfitting status of each individual attribute. A series of empirical evaluations in both settin...