With the increased capabilities at the edge (e.g., mobile device) and more stringent privacy requirement, it becomes a recent trend for deep learning-enabled applications to pre-process sensitive raw data at the edge and transmit the features to the backend cloud for further processing. A typical application is to run machine learning (ML) services on facial images collected from different individuals. To prevent identity theft, conventional methods commonly rely on an adversarial game-based approach to shed the identity information from the feature. However, such methods can not defend against adaptive attacks, in which an attacker takes a countermove against a known defence strategy. We propose Crafter, a feature crafting mechanism deployed at the edge, to protect the identity information from adaptive model inversion attacks while ensuring the ML tasks are properly carried out in the cloud. The key defence strategy is to mislead the attacker to a non-private prior from which the attacker gains little about the private identity. In this case, the crafted features act like poison training samples for attackers with adaptive model updates. Experimental results indicate that Crafter successfully defends both basic and possible adaptive attacks, which can not be achieved by state-of-the-art adversarial game-based methods.
翻译:摘要:随着边缘设备(如移动设备)能力的提升和隐私要求的日益严格,深度学习应用在边缘端预处理敏感原始数据,并将特征传输至云端后台进行进一步处理已成为近期趋势。一个典型应用是对从不同个体采集的面部图像运行机器学习服务。为防止身份窃取,传统方法通常依赖基于对抗博弈的方式从特征中剥离身份信息。然而,此类方法无法抵御自适应攻击——即攻击者针对已知防御策略采取反制措施。本文提出Crafter——一种部署于边缘端的特征伪造机制,旨在保护身份信息免受自适应模型反演攻击,同时确保机器学习任务在云端正常运行。核心防御策略是诱使攻击者陷入非隐私先验,使其几乎无法获取私有身份信息。在此情况下,对采用自适应模型更新的攻击者而言,伪造的特征如同有毒训练样本。实验结果表明,Crafter成功抵御了基础攻击及可能存在的自适应攻击,这是当前最优的基于对抗博弈的方法无法实现的。