Label‐only membership inference attacks on machine unlearning without dependence of posteriors. Issue 11 (17th August 2022)
- Record Type:
- Journal Article
- Title:
- Label‐only membership inference attacks on machine unlearning without dependence of posteriors. Issue 11 (17th August 2022)
- Main Title:
- Label‐only membership inference attacks on machine unlearning without dependence of posteriors
- Authors:
- Lu, Zhaobo
Liang, Hai
Zhao, Minghao
Lv, Qingzhe
Liang, Tiancai
Wang, Yilei - Abstract:
- Abstract: Machine unlearning is the process through which a deployed machine learning model is enforced to forget about some of its training data items. It normally generates two machine learning models, the original model and the unlearned model, indicating training results before and after data items are deleted. However, recent studies find that machine unlearning is vulnerable to membership inference attacks—as the directivity of training and nontraining data (i.e., data items in the training set have high posterior probabilities), the attackers can utilize this property to infer whether an item has been used for original model training. Nevertheless, such attacks are incapable in label‐only settings, in which the attackers are infeasible to get the posteriors. In this paper, we propose a new label‐only membership inference attack scheme targeted at machine unlearning to eliminate the dependence on posteriors. Our heuristic is that injected turbulence on candidate samples will present different behaviors for training and nontraining data. Thus, in our scheme, the attacker iteratively query on the original/unlearned models and inject turbulence to change their predicting labels; it determines whether an item is having‐been‐delated by observing the disturbance amplitude. Extensive experiments (i.e., on MNIST, CIFAR10, CIFAR100, and STL10 data sets) show that our method achieves high inference accuracy (measured by AUC) in label‐only settings, for example, AUC = 0.96 forAbstract: Machine unlearning is the process through which a deployed machine learning model is enforced to forget about some of its training data items. It normally generates two machine learning models, the original model and the unlearned model, indicating training results before and after data items are deleted. However, recent studies find that machine unlearning is vulnerable to membership inference attacks—as the directivity of training and nontraining data (i.e., data items in the training set have high posterior probabilities), the attackers can utilize this property to infer whether an item has been used for original model training. Nevertheless, such attacks are incapable in label‐only settings, in which the attackers are infeasible to get the posteriors. In this paper, we propose a new label‐only membership inference attack scheme targeted at machine unlearning to eliminate the dependence on posteriors. Our heuristic is that injected turbulence on candidate samples will present different behaviors for training and nontraining data. Thus, in our scheme, the attacker iteratively query on the original/unlearned models and inject turbulence to change their predicting labels; it determines whether an item is having‐been‐delated by observing the disturbance amplitude. Extensive experiments (i.e., on MNIST, CIFAR10, CIFAR100, and STL10 data sets) show that our method achieves high inference accuracy (measured by AUC) in label‐only settings, for example, AUC = 0.96 for MNIST data set. Besides, we analyze the existing countermeasures in mitigating inference attacks and find that our scheme can bypass most of them. … (more)
- Is Part Of:
- International journal of intelligent systems. Volume 37:Issue 11(2022)
- Journal:
- International journal of intelligent systems
- Issue:
- Volume 37:Issue 11(2022)
- Issue Display:
- Volume 37, Issue 11 (2022)
- Year:
- 2022
- Volume:
- 37
- Issue:
- 11
- Issue Sort Value:
- 2022-0037-0011-0000
- Page Start:
- 9424
- Page End:
- 9441
- Publication Date:
- 2022-08-17
- Subjects:
- label‐only -- machine unlearning -- membership inference attack
Artificial intelligence -- Periodicals
Expert systems (Computer science) -- Periodicals
Intelligence artificielle -- Périodiques
Systèmes experts (Informatique) -- Périodiques
006.3 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1098-111X ↗
https://www.hindawi.com/journals/ijis ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/int.23000 ↗
- Languages:
- English
- ISSNs:
- 0884-8173
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4542.310500
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 23918.xml