A sample’s distance from the decision boundary is a crucial indicator for predicting whether a given sample is a member of the training set in label-only membership inference attacks. Traditional attacks search for the minimum adversarial point for each sample to obtain the decision boundary distance and use a fixed threshold to determine if it is a member sample. However, during the search process, the randomness of the initial adversarial samples may lead to local optimal traps and, ultimately, to incorrect decision boundary distances. Similarly, a fixed threshold may lead to membership misclassification because there is some overlap in the distribution of decision boundary distances for members and nonmembers. To assess the problem of inaccurate decision boundary distances and misclassification, we propose a novel attack method under the label-only setting called the global adaptive membership inference attack. We propose a new low-dimensional rotational search algorithm to find the globally optimal initial point in the broader decision boundary, thus reducing the instability caused by random initial points. We also propose and employ the relative boundary distance instead of a single decision boundary distance to find an adaptive threshold for each sample. Extensive experiments show that our global adaptive MIA outperforms current label-only membership inference attacks in the CIFAR10 and CIFAR100 datasets, especially for the true positive rate at low false positive rates metric.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Optimizing Label-Only Membership Inference Attacks by Global Relative Decision Boundary Distances

  • Jiacheng Xu,
  • Jianpeng Hu,
  • Chunqing Yu,
  • Chengxiang Tan

摘要

A sample’s distance from the decision boundary is a crucial indicator for predicting whether a given sample is a member of the training set in label-only membership inference attacks. Traditional attacks search for the minimum adversarial point for each sample to obtain the decision boundary distance and use a fixed threshold to determine if it is a member sample. However, during the search process, the randomness of the initial adversarial samples may lead to local optimal traps and, ultimately, to incorrect decision boundary distances. Similarly, a fixed threshold may lead to membership misclassification because there is some overlap in the distribution of decision boundary distances for members and nonmembers. To assess the problem of inaccurate decision boundary distances and misclassification, we propose a novel attack method under the label-only setting called the global adaptive membership inference attack. We propose a new low-dimensional rotational search algorithm to find the globally optimal initial point in the broader decision boundary, thus reducing the instability caused by random initial points. We also propose and employ the relative boundary distance instead of a single decision boundary distance to find an adaptive threshold for each sample. Extensive experiments show that our global adaptive MIA outperforms current label-only membership inference attacks in the CIFAR10 and CIFAR100 datasets, especially for the true positive rate at low false positive rates metric.