1.Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,Hubei,China
2.Rizhao Institute of Information Technology,Wuhan University,Rizhao 276800,Shandong,China
3.Collaborative Innovation Center of Geospatial Technology,Wuhan 430079,Hubei,China
Show less
文章历史+
Received
Published
2022-04-06
2023-02-24
Issue Date
2026-07-23
PDF (1027K)
摘要
在以图像分类为目标任务的迁移学习场景下,针对攻击者能力和需求对应模型不一致的情况下攻击准确率较低的问题,提出面向特征向量差异性的成员推理攻击方案,构建阴影模型获取不同层次的特征向量,采用欧氏距离对不同特征向量之间的距离进行计算,提出阈值比较步骤对欧氏距离细化分类,并设计阈值选择策略。实验结果表明:在不访问教师模型的情况下,对教师模型实施成员推理攻击,所提攻击方案仍能实现较好的攻击性能。本文方案在Cats vs Dogs、Flowers102和CIFAR-100数据集上成员推理攻击准确率分别达到0.728、0.632和0.581,揭示了迁移学习场景下成员推理攻击的有效性。随着学生模型训练时冻结层数的增加,本文方案在Cats vs Dogs数据集上的攻击性能得到提升。
Abstract
In the transfer learning scenario with image classification as the target task, to solve the problem of low accuracy in the case of inconsistent corresponding models of the attacker's ability and demand, a membership inference attack scheme for feature vector difference is proposed, shadow model is constructed to help adversaries obtain feature vectors at different levels, and Euclidean distance is used to calculate the distance between different feature vectors. The threshold comparison step is proposed to classify Euclidean distance and a threshold selection strategy is also designed. Experimental results show that the proposed attack scheme can obtain great attack performance when attacking the teacher model without visiting the teacher model. The membership inference attack accuracy on Cats vs Dogs, Flowers102 and CIFAR-100 datasets achieves 0.728, 0.632 and 0.581 respectively, which reveals the effectiveness of membership inference attack in the transfer learning scenario. Moreover, with the increase of the number of frozen layers in student model training process, the attack performance of the proposed scheme on Cats vs Dogs datasets is improved.
本文在Cats vs Dogs、Flowers102和CIFAR-100数据集上分别对所提成员推理攻击方案进行实验评估,实验结果如表1所示。其中教师模型首先在ImageNet数据集上进行预训练,迁移后使用三个不同的数据集进行学生模型的训练。
本文所提攻击方案在Cats vs Dogs数据集上的攻击性能明显高于其他两个数据集,AUC指数达到了0.840,准确率达到了0.728。这是因为Cats vs Dogs数据集既没有CIFAR-100数据集的数据量大,也没有Flowers102的数据集类别多,学生模型在Cats vs Dogs数据集上进行迁移学习训练时,对于学生模型参数的改变程度也较小,因此在Cats vs Dogs数据集上,成员推理攻击的性能相对更好。同时,通过表1的数据可以发现,本文所提攻击方案在Flower102和CIFAR-100数据集上的AUC指数也接近0.7,准确率分别为0.632和0.581,这说明了成员推理攻击在迁移学习场景下是有效的。
进一步探究学生模型在迁移学习训练时的冻结层数,对成员推理攻击性能的影响。ResNet50[25]网络结构清晰明确,通常以维度降低的卷积层作为区分,将ResNet50网络结构分为五个部分。学生模型在Cats vs Dogs数据集上进行迁移学习训练,实验结果如表2所示。随着冻结部分的增加,本文攻击方案在Cats vs Dogs数据集上的攻击准确率分别达到了0.637,0.664和0.809。学生模型中被冻结的部分越多,本文提出的成员推理攻击方案的攻击性能越好。这是因为在迁移学习的模型迁移中,层次越高,特征越抽象。在学生模型训练的时候,为了更好地拟合学生模型的训练任务,这一部分的参数更新变化也更大。当冻结较高层的时候,学生模型对于学生数据集的拟合更差,保留了更多的教师模型训练数据的特征,因此攻击者具有更高的自信将特定数据记录判定为教师模型的成员数据。
WEIJ X, DUS K, YUZ X, et al. Review of white box adversarial attack technologies in image classification tasks [J]. Journal of Computer Applications, 2022,42(9):2732-2741. DOI:10.11772/j.issn.1001-9081-202107339(Ch ).
WEIZ C, FENGH, ZHANGX Q, et al. Research on physical adversarial sample detection method based on attention mechanism[J]. Application Research of Computers, 2022, 39(1): 254-258. DOI:10.19734/j.issn.1001-3695.2021.06.0255(Ch ).
[5]
TRAMÈRF, KURAKINA, PAPERNOTN, et al. Ensemble adversarial training: Attacks and defenses [DB/OL]. [2022-04-25].
[6]
FREDRIKSONM, LANTZE, JHA S, et al. Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing [C]// Proceedings of the 23rd USENIX Conference on Security Symposium. Berkeley : USENIX Association,2014: 17-32.
[7]
FREDRIKSONM, JHA S, RISTENPARTT. Model inversion attacks that exploit confidence information and basic countermeasures [C]// Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. New York : Association for Computing Machinery,2015: 1322-1333. DOI:10.1145/2810103.2813677 .
PENGC G, GAOT, LIUH L, et al. PCA-based membership inference attack for machine learning models[J]. Journal on Communications, 2022, 43(1): 149-160. DOI:10.11959/j.issn.1000-436x.2022009(Ch ).
[14]
SHOKRIR, STRONATIM, SONGC Z, et al. Membership inference attacks against machine learning models[C]//2017 IEEE Symposium on Security and Privacy. New York: IEEE Press, 2017: 3-18. DOI:10.1109/SP.2017.41 .
[15]
SALEMA, ZHANGY, HUMBERTM, et al. ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models [DB/OL]. [2022-02-03]. DOI: 10.14722/ndss.2019.23119 .
[16]
NASRM, SHOKRIR, HOUMANSADRA. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning [C]//2019 IEEE Symposium on Security and Privacy. New York: IEEE Press, 2019: 739-753. DOI:10.1109/SP.2019.00065 .
LIX, LIZ M, WEIJ H, et al. Cross-domain adaptive learning model based on feature separation [J]. Journal of Computer Research and Development, 2022, 59(1): 105-117. DOI:10.7544/issn1000-1239.20200765(Ch ).
[21]
YOSINSKIJ, CLUNEJ, BENGIOY, et al. How transferable are features in deep neural networks [J]. Advances in Neural Information Processing Systems, 2014, 4: 3320-3328.
LIY. Review of application of transfer learning in medical image analysis [J]. Computer Engineering and Applications, 2021, 57(20): 42-52. DOI:10.3778/j.issn.1002-8331.2106-0103(Ch ).
[24]
SHAHABIC. The Future of Driverless Cars[DB/OL]. [2022-02-01].
[25]
LIUD, FUJ, ZHANGY D, et al. Revision in continuous space: Unsupervised text style transfer without adversarial learning [J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2020, 34(5): 8376-8383. DOI:10.1609/aaai.v34i05.6355 .
[26]
WANGD, YES S, HUX H, et al. An end-to-end dialect identification system with transfer learning from a multilingual automatic speech recognition model [C]// Proc Interspeech 2021. 2021:374. Baixas: International Speech Communication Association, 2021: 3266-3270. DOI:10.21437/interspeech .
[27]
WANGB, YAOY, VISWANATHB, et al. With great training comes great vulnerability: Practical attacks against transfer learning [C]//Proceedings of the 27th USENIX Security Symposium. Berkeley : USENIX Association 2018: 1281-1297. DOI: 10.1080/23723556.2018.1509488 .
[28]
SCHUSTERR, SCHUSTERT, MERIY, et al. Humpty dumpty: Controlling word meanings via corpus poisoning [C]//2020 IEEE Symposium on Security and Privacy. New York: IEEE Press, 2020: 1295-1313. DOI:10.1109/SP40000.2020.00115 .
[29]
ZOUY, ZHANGZ K, BACKESM, et al. Privacy Analysis of Deep Learning in the Wild: Membership Inference Attacks Against Transfer Learning [EB/OL].[2022-01-01].
[30]
YEOMS, GIACOMELLII, FREDRIKSONM, et al. Privacy risk in machine learning: Analyzing the connection to overfitting [C]// 2018 IEEE 31st Computer Security Foundations Symposium. New York: IEEE Press, 2018: 268-282. DOI:10.1109/CSF.2018.00027 .
[31]
李航. 统计学习方法[M]. 北京:清华大学出版社, 2012.
[32]
LIH. Statistical Learning Method [M]. Beijing: Tsinghua University Press, 2012(Ch).
[33]
HEK M, ZHANGX Y, RENS Q, et al. Deep residual learning for image recognition [C]//2016 IEEE Conference on Computer Vision and Pattern Recognition. New York: IEEE Press, 2016: 770-778. DOI:10.1109/CVPR.2016.90 .