arrow
返回

Is Homomorphic Encryption-Based Deep Learning Secure Enough?

delete2021-11-24
delete4
delete
OA
AI
J
Jinmyeong Shin
S
Seok-Hwan Choi
Y
Yoon-Ho Choi *
DOI:10.3390/s21237806delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
As the amount of data collected and analyzed by machine learning technology increases, data that can identify individuals is also being collected in large quantities. In particular, as deep learning technology-which requires a large amount of analysis data-is activated in various service fields, the possibility of exposing sensitive information of users increases, and the user privacy problem is growing more than ever. As a solution to this user's data privacy problem, homomorphic encryption technology, which is an encryption technology that supports arithmetic operations using encrypted data, has been applied to various field including finance and health care in recent years. If so, is it possible to use the deep learning service while preserving the data privacy of users by using the data to which homomorphic encryption is applied? In this paper, we propose three attack methods to infringe user's data privacy by exploiting possible security vulnerabilities in the process of using homomorphic encryption-based deep learning services for the first time. To specify and verify the feasibility of exploiting possible security vulnerabilities, we propose three attacks: (1) an adversarial attack exploiting communication link between client and trusted party; (2) a reconstruction attack using the paired input and output data; and (3) a membership inference attack by malicious insider. In addition, we describe real-world exploit scenarios for financial and medical services. From the experimental evaluation results, we show that the adversarial example and reconstruction attacks are a practical threat to homomorphic encryption-based deep learning models. The adversarial attack decreased average classification accuracy from 0.927 to 0.043, and the reconstruction attack showed average reclassification accuracy of 0.888, respectively.
Keyword:
deep learning
privacy-preserving
homomorphic encryption
adversarial examples
reconstruction attack
membership inference attack
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Sensors 封面图
Sensors
IF:
3.5
论文数:
7.2W
被引数:
20.9W

机构

P
pusan national university
学者数:
2.1W
论文数: 1.9W
被引数: 20
引用论文

引用论文

err分享
err收藏
Parkinson's disease: Nigral receptor changes support peptidergic role in nigrostriatal modulation
err2004-10-08
err0
PREAI
errGeorge R. Uhl; Gail O. Hackney; Mary Torchia; Victoria Stranov; Wallace W. Tourtellotte; Peter J. Whitehouse; Vinh Tran; Steven Strittmatter
err分享
err收藏
Biological Effects of Proton Radiation: What We Know and Don't Know
err2013-03-01
err0
PREAI
errSwati Girdhani; Rainer Sachs; Lynn Hlatky
err分享
err收藏
学者 查看更多内容