Saved in:
Bibliographic Details
Main Authors: Ren, Heqing, Feng, Chao, Huertas, Alberto, Stiller, Burkhard
Format: Preprint
Published: 2025
Subjects:
Online Access:https://arxiv.org/abs/2505.07149
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916732301475840
author Ren, Heqing
Feng, Chao
Huertas, Alberto
Stiller, Burkhard
author_facet Ren, Heqing
Feng, Chao
Huertas, Alberto
Stiller, Burkhard
contents Traditional machine learning (ML) raises serious privacy concerns, while federated learning (FL) mitigates the risk of data leakage by keeping data on local devices. However, the training process of FL can still leak sensitive information, which adversaries may exploit to infer private data. One of the most prominent threats is the membership inference attack (MIA), where the adversary aims to determine whether a particular data record was part of the training set. This paper addresses this problem through a two-stage defense called AugMixCloak. The core idea is to apply data augmentation and principal component analysis (PCA)-based information fusion to query images, which are detected by perceptual hashing (pHash) as either identical to or highly similar to images in the training set. Experimental results show that AugMixCloak successfully defends against both binary classifier-based MIA and metric-based MIA across five datasets and various decentralized FL (DFL) topologies. Compared with regularization-based defenses, AugMixCloak demonstrates stronger protection. Compared with confidence score masking, AugMixCloak exhibits better generalization.
format Preprint
id arxiv_https___arxiv_org_abs_2505_07149
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AugMixCloak: A Defense against Membership Inference Attacks via Image Transformation
Ren, Heqing
Feng, Chao
Huertas, Alberto
Stiller, Burkhard
Machine Learning
Traditional machine learning (ML) raises serious privacy concerns, while federated learning (FL) mitigates the risk of data leakage by keeping data on local devices. However, the training process of FL can still leak sensitive information, which adversaries may exploit to infer private data. One of the most prominent threats is the membership inference attack (MIA), where the adversary aims to determine whether a particular data record was part of the training set. This paper addresses this problem through a two-stage defense called AugMixCloak. The core idea is to apply data augmentation and principal component analysis (PCA)-based information fusion to query images, which are detected by perceptual hashing (pHash) as either identical to or highly similar to images in the training set. Experimental results show that AugMixCloak successfully defends against both binary classifier-based MIA and metric-based MIA across five datasets and various decentralized FL (DFL) topologies. Compared with regularization-based defenses, AugMixCloak demonstrates stronger protection. Compared with confidence score masking, AugMixCloak exhibits better generalization.
title AugMixCloak: A Defense against Membership Inference Attacks via Image Transformation
topic Machine Learning
url https://arxiv.org/abs/2505.07149