University of Technology Sydney
Privacy Attacks and Defenses under Security Threats in Machine Learning
Abstract
dc:description.abstractMachine learning has been increasingly adopted across various domains due to its outstanding performance. However, machine learning models exhibit some vulnerabilities against threats in the real world, including privacy risks and security concerns. In terms of privacy risks, malicious users can steal the private information of other users or model owners, including recovering training data, inferring membership, and cloning the trained model without authentication. In terms of security, the functionality of machine learning models might be disrupted by malicious users. Both types of attacks pose challenges to the widespread deployment of machine learning models. However, these attacks are often studied separately, and their relationship is not well understood. To gain a better understanding of threats in machine learning, this thesis explores the interaction between privacy and security threats, especially the change in performance of privacy attacks and defenses when security attacks are present. Specifically, the contributions can be summarized as follows: 1.This thesis reveals that adversarial examples have the potential to enhance the reconstruction of private training data, implying that security vulnerabilities would amplify the privacy leakages in machine learning. This insight enables a more precise assessment of privacy threats. 2. We emphasize that adversarial attacks can escalate the privilege of attackers targeting compromising privacy. We propose a universal privacy attack framework that enhances the existing label-only attacks by recovering the confidence vectors. This framework bridges the gap between label-only and confidence-based attacks. 3. We introduce an innovative defense to prevent the reconstruction of private data, which incorporates data poisoning techniques as a defensive strategy. This strategy leverages the security vulnerabilities inherent in the models of attackers to diminish their performance, thereby preventing privacy leakage. This approach represents a benign application of security attacks. 4. We investigate the benign use of privacy attacks, leading to a defense mechanism against model stealing attacks. By exploiting model inversion attacks for data reconstruction, we can uncover the hidden patterns in the model's outputs, effectively creating a unique fingerprint for the model. This method allows us to detect the model stealing behaviors based on normal examples, eliminating the need for adversarial examples.
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Zhou, Shuai
Rights
dc:rights- Statement dc:rights
-
- info:eu-repo/semantics/openAccess
- The author owns the copyright in this thesis including all reproduction and reuse rights for the work. The work may not be altered without the permission of the copyright owner. Attribution is essential when quoting or paraphrasing from this thesis.
- © 2024 Shuai Zhou
- au.edu.uts.lib/cph
- Language dc:language.iso
- en_US
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- http://hdl.handle.net/10453/181087
- OAI identifier oai:identifier
- oai:opus.lib.uts.edu.au:10453/181087