OSLO: One-Shot Label-Only Membership Inference Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Peng, Yuefeng, Roh, Jaechul, Maji, Subhransu, Houmansadr, Amir
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929570907684864
author Peng, Yuefeng
Roh, Jaechul
Maji, Subhransu
Houmansadr, Amir
author_facet Peng, Yuefeng
Roh, Jaechul
Maji, Subhransu
Houmansadr, Amir
contents We introduce One-Shot Label-Only (OSLO) membership inference attacks (MIAs), which accurately infer a given sample's membership in a target model's training set with high precision using just \emph{a single query}, where the target model only returns the predicted hard label. This is in contrast to state-of-the-art label-only attacks which require $\sim6000$ queries, yet get attack precisions lower than OSLO's. OSLO leverages transfer-based black-box adversarial attacks. The core idea is that a member sample exhibits more resistance to adversarial perturbations than a non-member. We compare OSLO against state-of-the-art label-only attacks and demonstrate that, despite requiring only one query, our method significantly outperforms previous attacks in terms of precision and true positive rate (TPR) under the same false positive rates (FPR). For example, compared to previous label-only MIAs, OSLO achieves a TPR that is at least 7$\times$ higher under a 1\% FPR and at least 22$\times$ higher under a 0.1\% FPR on CIFAR100 for a ResNet18 model. We evaluated multiple defense mechanisms against OSLO.
format Preprint
id arxiv_https___arxiv_org_abs_2405_16978
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle OSLO: One-Shot Label-Only Membership Inference Attacks
Peng, Yuefeng
Roh, Jaechul
Maji, Subhransu
Houmansadr, Amir
Machine Learning
Cryptography and Security
We introduce One-Shot Label-Only (OSLO) membership inference attacks (MIAs), which accurately infer a given sample's membership in a target model's training set with high precision using just \emph{a single query}, where the target model only returns the predicted hard label. This is in contrast to state-of-the-art label-only attacks which require $\sim6000$ queries, yet get attack precisions lower than OSLO's. OSLO leverages transfer-based black-box adversarial attacks. The core idea is that a member sample exhibits more resistance to adversarial perturbations than a non-member. We compare OSLO against state-of-the-art label-only attacks and demonstrate that, despite requiring only one query, our method significantly outperforms previous attacks in terms of precision and true positive rate (TPR) under the same false positive rates (FPR). For example, compared to previous label-only MIAs, OSLO achieves a TPR that is at least 7$\times$ higher under a 1\% FPR and at least 22$\times$ higher under a 0.1\% FPR on CIFAR100 for a ResNet18 model. We evaluated multiple defense mechanisms against OSLO.
title OSLO: One-Shot Label-Only Membership Inference Attacks
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2405.16978