Matches in SemOpenAlex for { <https://semopenalex.org/work/W2952270003> ?p ?o ?g. }
- W2952270003 abstract "Large capacity machine learning models are prone to membership inference attacks in which an adversary aims to infer whether a particular data sample is a member of the target model's training dataset. Such membership inferences can lead to serious privacy violations as machine learning models are often trained using privacy-sensitive data such as medical records and controversial user opinions. Recently, defenses against membership inference attacks are developed, in particular, based on differential privacy and adversarial regularization; unfortunately, such defenses highly impact the classification accuracy of the underlying machine learning models. In this work, we present a new defense against membership inference attacks that preserves the utility of the target machine learning models significantly better than prior defenses. Our defense, called distillation for membership privacy (DMP), leverages knowledge distillation to train machine learning models with membership privacy. We analyze the key requirements for membership privacy and provide a novel criterion to select data used for knowledge transfer, in order to improve membership privacy of the final models. DMP works effectively against the attackers with either a whitebox or blackbox access to the target model. We evaluate DMP's performance through extensive experiments on different deep neural networks and using various benchmark datasets. We show that DMP provides a significantly better tradeoff between inference resistance and classification performance than state-of-the-art membership inference defenses. For instance, a DMP-trained DenseNet provides a classification accuracy of 65.3% for a 54.4% blackbox membership inference attack accuracy, while an adversarially regularized DenseNet provides a classification accuracy of only 53.7% for a (much worse) 68.7% blackbox membership inference attack accuracy." @default.
- W2952270003 created "2019-06-27" @default.
- W2952270003 creator A5018588864 @default.
- W2952270003 creator A5025710896 @default.
- W2952270003 date "2019-06-15" @default.
- W2952270003 modified "2023-09-27" @default.
- W2952270003 title "Reconciling Utility and Membership Privacy via Knowledge Distillation." @default.
- W2952270003 cites W1473189865 @default.
- W2952270003 cites W1515782956 @default.
- W2952270003 cites W1821462560 @default.
- W2952270003 cites W2027595342 @default.
- W2952270003 cites W2040228409 @default.
- W2952270003 cites W2051267297 @default.
- W2952270003 cites W2079115533 @default.
- W2952270003 cites W2101771965 @default.
- W2952270003 cites W2110287632 @default.
- W2952270003 cites W2119874464 @default.
- W2952270003 cites W2128906841 @default.
- W2952270003 cites W2134797427 @default.
- W2952270003 cites W2145287260 @default.
- W2952270003 cites W2183341477 @default.
- W2952270003 cites W2263253503 @default.
- W2952270003 cites W2435473771 @default.
- W2952270003 cites W2473418344 @default.
- W2952270003 cites W2520881573 @default.
- W2952270003 cites W2535690855 @default.
- W2952270003 cites W2591882872 @default.
- W2952270003 cites W2757528734 @default.
- W2952270003 cites W2767079719 @default.
- W2952270003 cites W2784621220 @default.
- W2952270003 cites W2788502731 @default.
- W2952270003 cites W2795435272 @default.
- W2952270003 cites W2798657499 @default.
- W2952270003 cites W2884943453 @default.
- W2952270003 cites W2891003389 @default.
- W2952270003 cites W2897830718 @default.
- W2952270003 cites W2903389359 @default.
- W2952270003 cites W2945528222 @default.
- W2952270003 cites W2946930197 @default.
- W2952270003 cites W2950602864 @default.
- W2952270003 cites W2952745707 @default.
- W2952270003 cites W2963378725 @default.
- W2952270003 cites W2963446712 @default.
- W2952270003 cites W2963456518 @default.
- W2952270003 cites W2963514416 @default.
- W2952270003 cites W2963844355 @default.
- W2952270003 cites W2964082701 @default.
- W2952270003 cites W2964318098 @default.
- W2952270003 cites W2967985550 @default.
- W2952270003 cites W2970708603 @default.
- W2952270003 cites W3118608800 @default.
- W2952270003 hasPublicationYear "2019" @default.
- W2952270003 type Work @default.
- W2952270003 sameAs 2952270003 @default.
- W2952270003 citedByCount "4" @default.
- W2952270003 countsByYear W29522700032020 @default.
- W2952270003 countsByYear W29522700032021 @default.
- W2952270003 countsByYear W29522700032022 @default.
- W2952270003 crossrefType "posted-content" @default.
- W2952270003 hasAuthorship W2952270003A5018588864 @default.
- W2952270003 hasAuthorship W2952270003A5025710896 @default.
- W2952270003 hasConcept C119857082 @default.
- W2952270003 hasConcept C124101348 @default.
- W2952270003 hasConcept C13280743 @default.
- W2952270003 hasConcept C154945302 @default.
- W2952270003 hasConcept C185798385 @default.
- W2952270003 hasConcept C205649164 @default.
- W2952270003 hasConcept C23130292 @default.
- W2952270003 hasConcept C26517878 @default.
- W2952270003 hasConcept C2776214188 @default.
- W2952270003 hasConcept C37736160 @default.
- W2952270003 hasConcept C38652104 @default.
- W2952270003 hasConcept C41008148 @default.
- W2952270003 hasConcept C41065033 @default.
- W2952270003 hasConcept C50644808 @default.
- W2952270003 hasConceptScore W2952270003C119857082 @default.
- W2952270003 hasConceptScore W2952270003C124101348 @default.
- W2952270003 hasConceptScore W2952270003C13280743 @default.
- W2952270003 hasConceptScore W2952270003C154945302 @default.
- W2952270003 hasConceptScore W2952270003C185798385 @default.
- W2952270003 hasConceptScore W2952270003C205649164 @default.
- W2952270003 hasConceptScore W2952270003C23130292 @default.
- W2952270003 hasConceptScore W2952270003C26517878 @default.
- W2952270003 hasConceptScore W2952270003C2776214188 @default.
- W2952270003 hasConceptScore W2952270003C37736160 @default.
- W2952270003 hasConceptScore W2952270003C38652104 @default.
- W2952270003 hasConceptScore W2952270003C41008148 @default.
- W2952270003 hasConceptScore W2952270003C41065033 @default.
- W2952270003 hasConceptScore W2952270003C50644808 @default.
- W2952270003 hasLocation W29522700031 @default.
- W2952270003 hasOpenAccess W2952270003 @default.
- W2952270003 hasPrimaryLocation W29522700031 @default.
- W2952270003 hasRelatedWork W2949492662 @default.
- W2952270003 hasRelatedWork W2977787364 @default.
- W2952270003 hasRelatedWork W2989576201 @default.
- W2952270003 hasRelatedWork W3010177353 @default.
- W2952270003 hasRelatedWork W3013068160 @default.
- W2952270003 hasRelatedWork W3081595899 @default.
- W2952270003 hasRelatedWork W3087067816 @default.
- W2952270003 hasRelatedWork W3095101874 @default.