Towards a Re-evaluation of Data Forging Attacks in Practice

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Suliman, Mohamed, Halimi, Anisa, Kadhe, Swanand, Baracaldo, Nathalie, Leith, Douglas
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915334423838720
author Suliman, Mohamed
Halimi, Anisa
Kadhe, Swanand
Baracaldo, Nathalie
Leith, Douglas
author_facet Suliman, Mohamed
Halimi, Anisa
Kadhe, Swanand
Baracaldo, Nathalie
Leith, Douglas
contents Data forging attacks provide counterfactual proof that a model was trained on a given dataset, when in fact, it was trained on another. These attacks work by forging (replacing) mini-batches with ones containing distinct training examples that produce nearly identical gradients. Data forging appears to break any potential avenues for data governance, as adversarial model owners may forge their training set from a dataset that is not compliant to one that is. Given these serious implications on data auditing and compliance, we critically analyse data forging from both a practical and theoretical point of view, finding that a key practical limitation of current attack methods makes them easily detectable by a verifier; namely that they cannot produce sufficiently identical gradients. Theoretically, we analyse the question of whether two distinct mini-batches can produce the same gradient. Generally, we find that while there may exist an infinite number of distinct mini-batches with real-valued training examples and labels that produce the same gradient, finding those that are within the allowed domain e.g. pixel values between 0-255 and one hot labels is a non trivial task. Our results call for the reevaluation of the strength of existing attacks, and for additional research into successful data forging, given the serious consequences it may have on machine learning and privacy.
format Preprint
id arxiv_https___arxiv_org_abs_2411_05658
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Towards a Re-evaluation of Data Forging Attacks in Practice
Suliman, Mohamed
Halimi, Anisa
Kadhe, Swanand
Baracaldo, Nathalie
Leith, Douglas
Cryptography and Security
Data forging attacks provide counterfactual proof that a model was trained on a given dataset, when in fact, it was trained on another. These attacks work by forging (replacing) mini-batches with ones containing distinct training examples that produce nearly identical gradients. Data forging appears to break any potential avenues for data governance, as adversarial model owners may forge their training set from a dataset that is not compliant to one that is. Given these serious implications on data auditing and compliance, we critically analyse data forging from both a practical and theoretical point of view, finding that a key practical limitation of current attack methods makes them easily detectable by a verifier; namely that they cannot produce sufficiently identical gradients. Theoretically, we analyse the question of whether two distinct mini-batches can produce the same gradient. Generally, we find that while there may exist an infinite number of distinct mini-batches with real-valued training examples and labels that produce the same gradient, finding those that are within the allowed domain e.g. pixel values between 0-255 and one hot labels is a non trivial task. Our results call for the reevaluation of the strength of existing attacks, and for additional research into successful data forging, given the serious consequences it may have on machine learning and privacy.
title Towards a Re-evaluation of Data Forging Attacks in Practice
topic Cryptography and Security
url https://arxiv.org/abs/2411.05658