Output regeneration defense against membership inference attacks for protecting data privacy

4Citations
Citations of this article
13Readers
Mendeley users who have this article in their library.

Abstract

Purpose: Recently, deep learning (DL) has been widely applied in various aspects of human endeavors. However, studies have shown that DL models may also be a primary cause of data leakage, which raises new data privacy concerns. Membership inference attacks (MIAs) are prominent threats to user privacy from DL model training data, as attackers investigate whether specific data samples exist in the training data of a target model. Therefore, the aim of this study is to develop a method for defending against MIAs and protecting data privacy. Design/methodology/approach: One possible solution is to propose an MIA defense method that involves adjusting the model’s output by mapping the output to a distribution with equal probability density. This approach effectively preserves the accuracy of classification predictions while simultaneously preventing attackers from identifying the training data. Findings: Experiments demonstrate that the proposed defense method is effective in reducing the classification accuracy of MIAs to below 50%. Because MIAs are viewed as a binary classification model, the proposed method effectively prevents privacy leakage and improves data privacy protection. Research limitations/implications: The method is only designed to defend against MIA in black-box classification models. Originality/value: The proposed MIA defense method is effective and has a low cost. Therefore, the method enables us to protect data privacy without incurring significant additional expenses.

Cite

CITATION STYLE

APA

Ding, Y., Huang, P., Liang, H., Yuan, F., & Wang, H. (2023). Output regeneration defense against membership inference attacks for protecting data privacy. International Journal of Web Information Systems, 19(2), 61–79. https://doi.org/10.1108/IJWIS-03-2023-0050

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free