跳到主要导航 跳到搜索 跳到主要内容

HAMIATCM: high-availability membership inference attack against text classification models under little knowledge

  • Yao Cheng
  • , Senlin Luo
  • , Limin Pan*
  • , Yunwei Wan
  • , Xinshuai Li
  • *此作品的通讯作者
  • Beijing Institute of Technology

科研成果: 期刊稿件文章同行评审

摘要

Membership inference attack opens up a newly emerging and rapidly growing research to steal user privacy from text classification models, a core problem of which is shadow model construction and members distribution optimization in inadequate members. The textual semantic is likely disrupted by simple text augmentation techniques, which weakens the correlation between labels and texts and reduces the precision of member classification. Shadow models trained exclusively with cross-entropy loss have little differentiation in embeddings among various classes, which deviates from the distribution of target models, then impacts the embeddings of members and reduces the F1 score. A competitive and High-Availability Membership Inference Attack against Text Classification Model (HAMIATCM) is proposed. At the data level, by selecting highly significant words and applying text augmentation techniques such as replacement or deletion, we expand knowledge of attackers, preserving vulnerable members to enhance the sensitive member distribution. At the model level, constructing contrastive loss and adaptive boundary loss to amplify the distribution differences among various classes, dynamically optimize the boundaries of members, enhancing the text representation capability of the shadow model and the classification performance of the attack classifier. Experimental results demonstrate that HAMIATCM achieves new state-of-the-art, significantly reduces the false positive rate, and strengthens the capability of fitting the output distribution of the target model with less knowledge of members.

源语言英语
页(从-至)7994-8019
页数26
期刊Applied Intelligence
54
17-18
DOI
出版状态已出版 - 9月 2024

指纹

探究 'HAMIATCM: high-availability membership inference attack against text classification models under little knowledge' 的科研主题。它们共同构成独一无二的指纹。

引用此