Lessons Learned: Defending Against Property Inference Attacks

6Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

This work investigates and evaluates defense strategies against property inference attacks (PIAs), a privacy attack against machine learning models. While for other privacy attacks like membership inference, a lot of research on defense mechanisms has been published, this is the first work focusing on defending against PIAs. One of the mitigation strategies we test in this paper is a novel proposal called property unlearning. Extensive experiments show that while this technique is very effective when defending against specific adversaries, it is not able to generalize, i.e., protect against a whole class of PIAs. To investigate the reasons behind this limitation, we present the results of experiments with the explainable AI tool LIME and the visualization technique t-SNE. These show how ubiquitous statistical properties of training data are in the parameters of a trained machine learning model. Hence, we develop the conjecture that post-training techniques like property unlearning might not suffice to provide the desirable generic protection against PIAs. We conclude with a discussion of different defense approaches, a summary of the lessons learned and directions for future work.

Cite

CITATION STYLE

APA

Stock, J., Wettlaufer, J., Demmler, D., & Federrath, H. (2023). Lessons Learned: Defending Against Property Inference Attacks. In Proceedings of the International Conference on Security and Cryptography (Vol. 1, pp. 312–323). Science and Technology Publications, Lda. https://doi.org/10.5220/0012049200003555

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free