The pervasive deployment of deep learning models across critical domains has concurrently intensified privacy concerns due to their inherent propensity for data memorization. While Membership Inference Attacks (MIAs) serve as the gold standard for auditing these privacy vulnerabilities, conventional MIA paradigms are increasingly constrained by the prohibitive computational costs of shadow model training and a precipitous performance degradation under low False Positive Rate constraints. To overcome these challenges, we introduce a novel perspective by leveraging the principles of model reprogramming as an active signal amplifier for privacy leakage. Building upon this insight, we present \texttt{ReproMIA}, a unified and efficient proactive framework for membership inference. We rigorously substantiate, both theoretically and empirically, how our methodology proactively induces and magnifies latent privacy footprints embedded within the model's representations. We provide specialized instantiations of \texttt{ReproMIA} across diverse architectural paradigms, including LLMs, Diffusion Models, and Classification Models. Comprehensive experimental evaluations across more than ten benchmarks and a variety of model architectures demonstrate that \texttt{ReproMIA} consistently and substantially outperforms existing state-of-the-art baselines, achieving a transformative leap in performance specifically within low-FPR regimes, such as an average of 5.25\% AUC and 10.68\% TPR@1\%FPR increase over the runner-up for LLMs, as well as 3.70\% and 12.40\% respectively for Diffusion Models.


翻译:深度学习模型在关键领域的广泛部署,因其固有的数据记忆倾向而加剧了隐私担忧。尽管成员推理攻击(MIA)是审计这些隐私漏洞的金标准,但传统的MIA范式正日益受到影子模型训练高昂计算成本及低假阳性率约束下性能急剧下降的限制。为克服这些挑战,我们引入了一种新颖视角,利用模型重编程原理作为隐私泄露的主动信号放大器。基于这一洞见,我们提出了统一且高效的主动推理框架\texttt{ReproMIA}。通过理论与实证双重验证,我们严格论证了该方法如何主动诱发并放大嵌入模型表征中的潜在隐私足迹。我们针对LLM、扩散模型及分类模型等不同架构范式提供了\texttt{ReproMIA}的专门实例化方案。在十余个基准数据集及多种模型架构上的全面实验评估表明,\texttt{ReproMIA}持续且显著优于现有最先进基线,尤其在低FPR场景中实现了变革性性能突破:例如在LLM任务中,AUC和TPR@1%FPR平均较第二名分别提升5.25%和10.68%;在扩散模型中相应提升分别达3.70%和12.40%。

0
下载
关闭预览

相关内容

深度学习模型反演攻击与防御:全面综述
专知会员服务
27+阅读 · 2025年2月3日
深度学习模型安全:威胁与防御,176页pdf
专知会员服务
28+阅读 · 2024年12月13日
专知会员服务
24+阅读 · 2021年8月22日
专知会员服务
49+阅读 · 2021年5月17日
【AAAI2021】知识迁移的机器学习成员隐私保护,57页ppt
专知会员服务
28+阅读 · 2021年2月9日
专知会员服务
97+阅读 · 2021年1月17日
专知会员服务
68+阅读 · 2021年1月10日
深度学习模型可解释性的研究进展
专知
26+阅读 · 2020年8月1日
推荐召回算法之深度召回模型串讲
AINLP
22+阅读 · 2019年6月14日
从Seq2seq到Attention模型到Self Attention(一)
量化投资与机器学习
76+阅读 · 2018年10月8日
机器学习模型的“可解释性”到底有多重要?
中国科学院自动化研究所
20+阅读 · 2018年3月1日
展望:模型驱动的深度学习
人工智能学家
12+阅读 · 2018年1月23日
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
12+阅读 · 2015年12月31日
国家自然科学基金
13+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
VIP会员
相关主题
最新内容
边缘计算的军事应用
专知会员服务
7+阅读 · 8月9日
一种考虑资源机动性的武器目标分配混合算法
专知会员服务
9+阅读 · 8月8日
《多域冲突比较支持模型》60页
专知会员服务
14+阅读 · 8月7日
相关VIP内容
深度学习模型反演攻击与防御:全面综述
专知会员服务
27+阅读 · 2025年2月3日
深度学习模型安全:威胁与防御,176页pdf
专知会员服务
28+阅读 · 2024年12月13日
专知会员服务
24+阅读 · 2021年8月22日
专知会员服务
49+阅读 · 2021年5月17日
【AAAI2021】知识迁移的机器学习成员隐私保护,57页ppt
专知会员服务
28+阅读 · 2021年2月9日
专知会员服务
97+阅读 · 2021年1月17日
专知会员服务
68+阅读 · 2021年1月10日
相关基金
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
12+阅读 · 2015年12月31日
国家自然科学基金
13+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员