Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
Explore this paper's citation graph
Summary
The reasons why deep learning models may leak information about their training data are investigated and new algorithms tailored to the white-box setting are designed by exploiting the privacy vulnerabilities of the stochastic gradient descent algorithm, which is the algorithm used to train deep neural networks.
- Type
- article
- Published
- 2018-12-03
- Cited by
- 1,893
- References
- 40
- Access
- Open access
- OpenAlex
- https://openalex.org/W2930926105
- Semantic Scholar
- https://api.semanticscholar.org/CorpusID:133091488
Keywords
Inference, Computer science, Deep learning, Artificial intelligence, Machine learning
References
- Private Empirical Risk Minimization: Efficient Algorithms and Tight Error Bounds
- The Algorithmic Foundations of Differential Privacy
- Resolving Individuals Contributing Trace Amounts of DNA to Highly Complex Mixtures Using High-Density SNP Genotyping Microarrays
- Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures
- Privacy-preserving deep learning
- Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers
- Revealing information while preserving privacy
- Differentially Private Empirical Risk Minimization
- A tutorial on spectral clustering
- Learning your identity and disease from research papers: information leaks in genome wide association study
- ImageNet classification with deep convolutional neural networks
- Deep Residual Learning for Image Recognition
- Robust Traceability from Trace Amounts
- Deep Learning with Differential Privacy
- Calibrating Noise to Sensitivity in Private Data Analysis
- Exposed! A Survey of Attacks on Private Data
- Minimax Filter: Learning to Preserve Privacy from Inference Attacks
- Membership Inference Attacks Against Machine Learning Models
- Federated Learning: Strategies for Improving Communication Efficiency
- Communication-Efficient Learning of Deep Networks from Decentralized Data
Cited by
- The effect of child sexual exploitation images collection size on offender sentencing
- Updates-Leak: Data Set Inference and Reconstruction Attacks in Online Learning
- Privacy Risks of Securing Machine Learning Models against Adversarial Examples
- Mobile Edge Computing, Blockchain and Reputation-based Crowdsourcing IoT Federated Learning: A Secure, Decentralized and Privacy-preserving System
- MIASec: Enabling Data Indistinguishability Against Membership Inference Attacks in MLaaS
- A Federated Learning Approach for Mobile Packet Classification
- Membership Inference Attacks Against Adversarially Robust Deep Learning Models
- Membership Encoding for Deep Learning
- Ultimate Power of Inference Attacks: Privacy Risks of High-Dimensional Models
- Central Server Free Federated Learning over Single-sided Trust Social Networks
- Eavesdrop the Composition Proportion of Training Labels in Federated Learning
- MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples
- Federated Learning for Healthcare Informatics
- Poster: Towards Characterizing and Limiting Information Exposure in DNN Layers
- A Survey on Federated Learning Systems: Vision, Hype and Reality for Data Privacy and Protection
- On the Intrinsic Privacy of Stochastic Gradient Descent
- Preventing Information Leakage with Neural Architecture Search
- Privacy for All: Demystify Vulnerability Disparity of Differential Privacy against Membership Inference Attack
- PrivacyFL: A Simulator for Privacy-Preserving and Secure Federated Learning
- Resource Usage and Performance Trade-offs for Machine Learning Models in Smart Environments
Related papers
- Semi-mechanistic modeling of chemical processes with neural networks
- Tool-box frameworks - the new challenge beyond black-box and white-box
- Semi-Physical Modeling of Chemical Processes with Neural Networks
- Using MC/DC as a black-box testing technique
- Comparison of black-box, glass-box and open-box software for aiding conceptual understanding
- On membership of black-box or white-box of artificial neural network models
- On Black Box Tests and White Box Tests