NDSS 2019 ML-Leaks: Inference Attacks and Defenses on Machine Learning Models

Опубликовано: 04 Март 2026
на канале: NDSS Symposium
2,021
20

SESSION 3A-1 ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models

Machine learning (ML) has become a core component of many real-world applications and training data is a key factor that drives current progress. This huge success has led Internet companies to deploy machine learning as a service (MLaaS). Recently, the first membership inference attack has shown that extraction of information on the training set is possible in such MLaaS settings, which has severe security and privacy implications.

However, the early demonstrations of the feasibility of such attacks have many assumptions on the adversary, such as using multiple so-called shadow models, knowledge of the target model structure, and having a dataset from the same distribution as the target model's training data. We relax all these key assumptions, thereby showing that such attacks are very broadly applicable at low cost and thereby pose a more severe risk than previously thought. We present the most comprehensive study so far on this emerging and developing threat using eight diverse datasets which show the viability of the proposed attacks across domains.

In addition, we propose the first effective defense mechanisms against such broader class of membership inference attacks that maintain a high level of utility of the ML model.

PAPER
https://www.ndss-symposium.org/wp-con...

SLIDES
https://www.ndss-symposium.org/wp-con...

AUTHORS
Ahmed Salem (CISPA Helmholtz Center for Information Security)
Yang Zhang (CISPA Helmholtz Center for Information Security)
Mathias Humbert (Swiss Data Science Center, ETH Zurich/EPFL)
Pascal Berrang (CISPA Helmholtz Center for Information Security)
Mario Fritz (CISPA Helmholtz Center for Information Security)
Michael Backes (CISPA Helmholtz Center for Information Security)


Network and Distributed System Security (NDSS) Symposium 2019, 24-27 February 2019, Catamaran Resort Hotel & Spa in San Diego, California.
https://www.ndss-symposium.org/ndss-p...


ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.
https://www.ndss-symposium.org/

#NDSS #NDSS19 #NDSS2019 #InternetSecurity