Hide in Plain Sight: Clean-Label Backdoor for Auditing Membership Inference

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Chen, Depeng, Chen, Hao, Jin, Hulin, Cui, Jie, Zhong, Hong
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917848701468672
author Chen, Depeng
Chen, Hao
Jin, Hulin
Cui, Jie
Zhong, Hong
author_facet Chen, Depeng
Chen, Hao
Jin, Hulin
Cui, Jie
Zhong, Hong
contents Membership inference attacks (MIAs) are critical tools for assessing privacy risks and ensuring compliance with regulations like the General Data Protection Regulation (GDPR). However, their potential for auditing unauthorized use of data remains under explored. To bridge this gap, we propose a novel clean-label backdoor-based approach for MIAs, designed specifically for robust and stealthy data auditing. Unlike conventional methods that rely on detectable poisoned samples with altered labels, our approach retains natural labels, enhancing stealthiness even at low poisoning rates. Our approach employs an optimal trigger generated by a shadow model that mimics the target model's behavior. This design minimizes the feature-space distance between triggered samples and the source class while preserving the original data labels. The result is a powerful and undetectable auditing mechanism that overcomes limitations of existing approaches, such as label inconsistencies and visual artifacts in poisoned samples. The proposed method enables robust data auditing through black-box access, achieving high attack success rates across diverse datasets and model architectures. Additionally, it addresses challenges related to trigger stealthiness and poisoning durability, establishing itself as a practical and effective solution for data auditing. Comprehensive experiments validate the efficacy and generalizability of our approach, outperforming several baseline methods in both stealth and attack success metrics.
format Preprint
id arxiv_https___arxiv_org_abs_2411_16763
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Hide in Plain Sight: Clean-Label Backdoor for Auditing Membership Inference
Chen, Depeng
Chen, Hao
Jin, Hulin
Cui, Jie
Zhong, Hong
Cryptography and Security
Artificial Intelligence
Machine Learning
Membership inference attacks (MIAs) are critical tools for assessing privacy risks and ensuring compliance with regulations like the General Data Protection Regulation (GDPR). However, their potential for auditing unauthorized use of data remains under explored. To bridge this gap, we propose a novel clean-label backdoor-based approach for MIAs, designed specifically for robust and stealthy data auditing. Unlike conventional methods that rely on detectable poisoned samples with altered labels, our approach retains natural labels, enhancing stealthiness even at low poisoning rates. Our approach employs an optimal trigger generated by a shadow model that mimics the target model's behavior. This design minimizes the feature-space distance between triggered samples and the source class while preserving the original data labels. The result is a powerful and undetectable auditing mechanism that overcomes limitations of existing approaches, such as label inconsistencies and visual artifacts in poisoned samples. The proposed method enables robust data auditing through black-box access, achieving high attack success rates across diverse datasets and model architectures. Additionally, it addresses challenges related to trigger stealthiness and poisoning durability, establishing itself as a practical and effective solution for data auditing. Comprehensive experiments validate the efficacy and generalizability of our approach, outperforming several baseline methods in both stealth and attack success metrics.
title Hide in Plain Sight: Clean-Label Backdoor for Auditing Membership Inference
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2411.16763