Abstract
This work investigates and evaluates defense strategies against property inference attacks (PIAs), a privacy attack against machine learning models. While for other privacy attacks like membership inference, a lot of research on defense mechanisms has been published, this is the first work focusing on defending against PIAs. One of the mitigation strategies we test in this paper is a novel proposal called property unlearning. Extensive experiments show that while this technique is very effective when defending against specific adversaries, it is not able to generalize, i.e., protect against a whole class of PIAs. To investigate the reasons behind this limitation, we present the results of experiments with the explainable AI tool LIME and the visualization technique t-SNE. These show how ubiquitous statistical properties of training data are in the parameters of a trained machine learning model. Hence, we develop the conjecture that post-training techniques like property unlearning might not suffice to provide the desirable generic protection against PIAs. We conclude with a discussion of different defense approaches, a summary of the lessons learned and directions for future work.
Author supplied keywords
Cite
CITATION STYLE
Stock, J., Wettlaufer, J., Demmler, D., & Federrath, H. (2023). Lessons Learned: Defending Against Property Inference Attacks. In Proceedings of the International Conference on Security and Cryptography (Vol. 1, pp. 312–323). Science and Technology Publications, Lda. https://doi.org/10.5220/0012049200003555
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.