Membership Inference Attacks against GANs by Leveraging Over-representation Regions

31Citations
Citations of this article
15Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Generative adversarial networks (GANs) have made unprecedented performance in image synthesis and play a key role in various downstream applications of computer vision. However, GAN models trained on sensitive data also pose a distinct threat to privacy. In this poster, we present a novel over-representation based membership inference attack. Unlike prior attacks against GANs which focus on the overall metrics, such as the attack accuracy, our attack aims to make inference from the high-precision perspective, which allows the adversary to concentrate on inferring a sample as a member confidently. Initial experimental results demonstrate that the adversary can achieve a high precision attack even if the overall attack accuracy is about 50% for a well-trained GAN model. Our work will raise awareness of the importance of precision when GAN owners evaluate the privacy risks of their models.

Cite

CITATION STYLE

APA

Hu, H., & Pang, J. (2021). Membership Inference Attacks against GANs by Leveraging Over-representation Regions. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 2387–2389). Association for Computing Machinery. https://doi.org/10.1145/3460120.3485338

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free