Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature Filtering
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | , , , , , , , , |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2024
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866917116642328576 |
|---|---|
| author | Yu, Hongyao Qiu, Yixiang Fang, Hao Zhuang, Tianqu Chen, Bin Yu, Sijin Wang, Bin Xia, Shu-Tao Xu, Ke |
| author_facet | Yu, Hongyao Qiu, Yixiang Fang, Hao Zhuang, Tianqu Chen, Bin Yu, Sijin Wang, Bin Xia, Shu-Tao Xu, Ke |
| contents | Model Inversion Attacks (MIAs) pose a significant threat to data privacy by reconstructing sensitive training samples from the knowledge embedded in trained machine learning models. Despite recent progress in enhancing the effectiveness of MIAs across diverse settings, defense strategies have lagged behind, struggling to balance model utility with robustness against increasingly sophisticated attacks. In this work, we propose the ideal inversion error to measure the privacy leakage, and our theoretical and empirical investigations reveals that higher-rank features are inherently more prone to privacy leakage. Motivated by this insight, we propose a lightweight and effective defense strategy based on low-rank feature filtering, which explicitly reduces the attack surface by constraining the dimension of intermediate representations. Extensive experiments across various model architectures and datasets demonstrate that our method consistently outperforms existing defenses, achieving state-of-the-art performance against a wide range of MIAs. Notably, our approach remains effective even in challenging regimes involving high-resolution data and high-capacity models, where prior defenses fail to provide adequate protection. The code is available at https://github.com/Chrisqcwx/LoFt . |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2410_05814 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature Filtering Yu, Hongyao Qiu, Yixiang Fang, Hao Zhuang, Tianqu Chen, Bin Yu, Sijin Wang, Bin Xia, Shu-Tao Xu, Ke Cryptography and Security Computer Vision and Pattern Recognition Machine Learning Model Inversion Attacks (MIAs) pose a significant threat to data privacy by reconstructing sensitive training samples from the knowledge embedded in trained machine learning models. Despite recent progress in enhancing the effectiveness of MIAs across diverse settings, defense strategies have lagged behind, struggling to balance model utility with robustness against increasingly sophisticated attacks. In this work, we propose the ideal inversion error to measure the privacy leakage, and our theoretical and empirical investigations reveals that higher-rank features are inherently more prone to privacy leakage. Motivated by this insight, we propose a lightweight and effective defense strategy based on low-rank feature filtering, which explicitly reduces the attack surface by constraining the dimension of intermediate representations. Extensive experiments across various model architectures and datasets demonstrate that our method consistently outperforms existing defenses, achieving state-of-the-art performance against a wide range of MIAs. Notably, our approach remains effective even in challenging regimes involving high-resolution data and high-capacity models, where prior defenses fail to provide adequate protection. The code is available at https://github.com/Chrisqcwx/LoFt . |
| title | Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature Filtering |
| topic | Cryptography and Security Computer Vision and Pattern Recognition Machine Learning |
| url | https://arxiv.org/abs/2410.05814 |