Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative Models

About

Deep learning has achieved overwhelming success, spanning from discriminative models to generative models. In particular, deep generative models have facilitated a new level of performance in a myriad of areas, ranging from media manipulation to sanitized dataset generation. Despite the great success, the potential risks of privacy breach caused by generative models have not been analyzed systematically. In this paper, we focus on membership inference attack against deep generative models that reveals information about the training data used for victim models. Specifically, we present the first taxonomy of membership inference attacks, encompassing not only existing attacks but also our novel ones. In addition, we propose the first generic attack model that can be instantiated in a large range of settings and is applicable to various kinds of deep generative models. Moreover, we provide a theoretically grounded attack calibration technique, which consistently boosts the attack performance in all cases, across different attack settings, data modalities, and training configurations. We complement the systematic analysis of attack performance by a comprehensive experimental study, that investigates the effectiveness of various attacks w.r.t. model type and training configurations, over three diverse application scenarios (i.e., images, medical data, and location data).

Dingfan Chen, Ning Yu, Yang Zhang, Mario Fritz• 2019

Related benchmarks

TaskDatasetResultRank
Membership Inference AttackCIFAR-100
TPR @ 1% FPR1.85
46
Membership Inference Attack RankingSynthetic Data Release (1,525 runs)
Top-1 Success Rate18.4
45
Membership Inference AttackSynthetic Data Release (top 100 runs)
AUC0.579
18
Membership Inference AttackCalifornia
AUC0.79
16
Membership Inference AttackAirbnb
AUC0.79
8
Membership Inference AttackAirlines
AUC0.69
6
Membership Inference AttackStable Diffusion V1.4
ASR53.3
4
Membership Inference AttackStable Diffusion v1.5
ASR54.1
4
Membership Inference AttackCIFAR-10
TPR @ 1% FPR2.8
4
Membership Inference AttackTiny-ImageNet
TPR @ 1% FPR1.01
4
Showing 10 of 14 rows

Other info

Follow for update