arrow
Return

A GAN-Based Defense Framework Against Model Inversion Attacks

delete2023-01-01
delete5
PRE
AI
X
Xueluan Gong
Z
Ziyao Wang
S
Shuaike Li
陈彦交 cover
陈彦交 (Yanjiao Chen) *
王茜 cover
王茜 (Qian Wang) *
DOI:10.1109/TIFS.2023.3295944delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
With the development of deep learning, deep neural network (DNN)-based application have become an indispensable aspect of daily life. However, recent studies have shown that these well-trained DNN models are vulnerable to model inversion attacks (MIAs), where attackers can recover their training data with high fidelity. Although several defensive strategies have been proposed to mitigate the impact of such attacks, existing defenses will inevitably compromise the model performance and are ineffective against more sophisticated attacks, such as Mirror (An et al., 2022). In this paper, we introduce a novel GAN-based defense approach against model inversion attacks. Unlike previous works that perturb the prediction vector of the model, we manipulate the training procedure of the victim model by incorporating carefully-designed GAN-based fake samples. We also adjust the loss of the inversed samples to inject misleading features into the protected label of the victim model. Additionally, we adopt the concept of continual learning to improve the utility of the model. Extensive experiments conducted on the CelebA, VGG-Face, and VGG-Face2 datasets demonstrate that our proposed method outperforms existing defenses against state-of-the-art model inversion attacks, including DMI (Chen et al., 2021), Mirror (An et al., 2022), Privacy (Fredrikson et al., 2014), and AMI (Yang et al., 2019). It is shown that our proposed method can also retain a high defense performance in black-box scenarios.
Keywords:
Model inversion attacks
GAN-based fake sample generation
privacy-utility defense framework

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.3K
Citations:
2.3W

Organization

W
wuhan university
Scholars:
8.1W
Papers: 5.8W
Citations: 70
Z
zhejiang university
Scholars:
17.7W
Papers: 12.1W
Citations: 152
Cited Papers

Cited Papers

Intuitive Welding Robot Programming via Motion Capture and Augmented Reality
err2019-01-01
err0
errOAAI
errFabian Mueller; Christian Deuerlein; Michael Koch
errShare
errSave
errShare
errSave
Breakdown of the Mott-Hubbard State inFe2O3: A First-Order Insulator-Metal Transition with Collapse of Magnetism at 50 GPa
err1999-06-07
err0
PREAI
errM. P. Pasternak; G. Kh. Rozenberg; G. Yu. Machavariani; O. Naaman; R. D. Taylor; R. Jeanloz
errShare
errSave
err
IF0
err2022-12-02
err0
PREAI
err
errShare
errSave
Dengue 2 genotypes in the state of Oaxaca, Mexico
err2005-08-12
err0
errOAAI
errA. Cisneros; Á. Díaz-Badillo; G. Cruz-Martínez; R. Tovar; L. R. Ramírez-Palacios; F. Jiménez-Rojas; B. Beaty; W. C. Black; M. de Lourdes Muñoz
errShare
errSave
researcher View more