Model Inversion Robustness: Can Transfer Learning Help?

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Ho, Sy-Tuyen, Hao, Koh Jun, Chandrasegaran, Keshigeyan, Nguyen, Ngoc-Bao, Cheung, Ngai-Man
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866911871417712640
author Ho, Sy-Tuyen
Hao, Koh Jun
Chandrasegaran, Keshigeyan
Nguyen, Ngoc-Bao
Cheung, Ngai-Man
author_facet Ho, Sy-Tuyen
Hao, Koh Jun
Chandrasegaran, Keshigeyan
Nguyen, Ngoc-Bao
Cheung, Ngai-Man
contents Model Inversion (MI) attacks aim to reconstruct private training data by abusing access to machine learning models. Contemporary MI attacks have achieved impressive attack performance, posing serious threats to privacy. Meanwhile, all existing MI defense methods rely on regularization that is in direct conflict with the training objective, resulting in noticeable degradation in model utility. In this work, we take a different perspective, and propose a novel and simple Transfer Learning-based Defense against Model Inversion (TL-DMI) to render MI-robust models. Particularly, by leveraging TL, we limit the number of layers encoding sensitive information from private training dataset, thereby degrading the performance of MI attack. We conduct an analysis using Fisher Information to justify our method. Our defense is remarkably simple to implement. Without bells and whistles, we show in extensive experiments that TL-DMI achieves state-of-the-art (SOTA) MI robustness. Our code, pre-trained models, demo and inverted data are available at: https://hosytuyen.github.io/projects/TL-DMI
format Preprint
id arxiv_https___arxiv_org_abs_2405_05588
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Model Inversion Robustness: Can Transfer Learning Help?
Ho, Sy-Tuyen
Hao, Koh Jun
Chandrasegaran, Keshigeyan
Nguyen, Ngoc-Bao
Cheung, Ngai-Man
Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
Model Inversion (MI) attacks aim to reconstruct private training data by abusing access to machine learning models. Contemporary MI attacks have achieved impressive attack performance, posing serious threats to privacy. Meanwhile, all existing MI defense methods rely on regularization that is in direct conflict with the training objective, resulting in noticeable degradation in model utility. In this work, we take a different perspective, and propose a novel and simple Transfer Learning-based Defense against Model Inversion (TL-DMI) to render MI-robust models. Particularly, by leveraging TL, we limit the number of layers encoding sensitive information from private training dataset, thereby degrading the performance of MI attack. We conduct an analysis using Fisher Information to justify our method. Our defense is remarkably simple to implement. Without bells and whistles, we show in extensive experiments that TL-DMI achieves state-of-the-art (SOTA) MI robustness. Our code, pre-trained models, demo and inverted data are available at: https://hosytuyen.github.io/projects/TL-DMI
title Model Inversion Robustness: Can Transfer Learning Help?
topic Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2405.05588