Matches in SemOpenAlex for { <https://semopenalex.org/work/W4292260100> ?p ?o ?g. }
- W4292260100 endingPage "9441" @default.
- W4292260100 startingPage "9424" @default.
- W4292260100 abstract "Machine unlearning is the process through which a deployed machine learning model is enforced to forget about some of its training data items. It normally generates two machine learning models, the original model and the unlearned model, indicating training results before and after data items are deleted. However, recent studies find that machine unlearning is vulnerable to membership inference attacks—as the directivity of training and nontraining data (i.e., data items in the training set have high posterior probabilities), the attackers can utilize this property to infer whether an item has been used for original model training. Nevertheless, such attacks are incapable in label-only settings, in which the attackers are infeasible to get the posteriors. In this paper, we propose a new label-only membership inference attack scheme targeted at machine unlearning to eliminate the dependence on posteriors. Our heuristic is that injected turbulence on candidate samples will present different behaviors for training and nontraining data. Thus, in our scheme, the attacker iteratively query on the original/unlearned models and inject turbulence to change their predicting labels; it determines whether an item is having-been-delated by observing the disturbance amplitude. Extensive experiments (i.e., on MNIST, CIFAR10, CIFAR100, and STL10 data sets) show that our method achieves high inference accuracy (measured by AUC) in label-only settings, for example, AUC = 0.96 for MNIST data set. Besides, we analyze the existing countermeasures in mitigating inference attacks and find that our scheme can bypass most of them." @default.
- W4292260100 created "2022-08-19" @default.
- W4292260100 creator A5002117529 @default.
- W4292260100 creator A5042914490 @default.
- W4292260100 creator A5052947690 @default.
- W4292260100 creator A5055652863 @default.
- W4292260100 creator A5058533368 @default.
- W4292260100 creator A5089236349 @default.
- W4292260100 date "2022-08-17" @default.
- W4292260100 modified "2023-09-24" @default.
- W4292260100 title "Label‐only membership inference attacks on machine unlearning without dependence of posteriors" @default.
- W4292260100 cites W1488996941 @default.
- W4292260100 cites W2111547563 @default.
- W4292260100 cites W2112796928 @default.
- W4292260100 cites W2123147099 @default.
- W4292260100 cites W2194775991 @default.
- W4292260100 cites W2535690855 @default.
- W4292260100 cites W2757528734 @default.
- W4292260100 cites W2797558164 @default.
- W4292260100 cites W2807140409 @default.
- W4292260100 cites W2887995258 @default.
- W4292260100 cites W2910774907 @default.
- W4292260100 cites W2914247668 @default.
- W4292260100 cites W2923095117 @default.
- W4292260100 cites W2930926105 @default.
- W4292260100 cites W2952604841 @default.
- W4292260100 cites W2963378725 @default.
- W4292260100 cites W2965527189 @default.
- W4292260100 cites W2983140679 @default.
- W4292260100 cites W2997507814 @default.
- W4292260100 cites W3071470454 @default.
- W4292260100 cites W3110283378 @default.
- W4292260100 cites W3110470025 @default.
- W4292260100 cites W3113540817 @default.
- W4292260100 cites W3120349939 @default.
- W4292260100 cites W3122211423 @default.
- W4292260100 cites W3128108456 @default.
- W4292260100 cites W3132199788 @default.
- W4292260100 cites W3154155772 @default.
- W4292260100 cites W3174532363 @default.
- W4292260100 cites W3193479815 @default.
- W4292260100 cites W3208464986 @default.
- W4292260100 cites W3214437258 @default.
- W4292260100 cites W3214586949 @default.
- W4292260100 cites W4285122420 @default.
- W4292260100 cites W4292793961 @default.
- W4292260100 cites W4312595359 @default.
- W4292260100 doi "https://doi.org/10.1002/int.23000" @default.
- W4292260100 hasPublicationYear "2022" @default.
- W4292260100 type Work @default.
- W4292260100 citedByCount "4" @default.
- W4292260100 countsByYear W42922601002023 @default.
- W4292260100 crossrefType "journal-article" @default.
- W4292260100 hasAuthorship W4292260100A5002117529 @default.
- W4292260100 hasAuthorship W4292260100A5042914490 @default.
- W4292260100 hasAuthorship W4292260100A5052947690 @default.
- W4292260100 hasAuthorship W4292260100A5055652863 @default.
- W4292260100 hasAuthorship W4292260100A5058533368 @default.
- W4292260100 hasAuthorship W4292260100A5089236349 @default.
- W4292260100 hasBestOaLocation W42922601001 @default.
- W4292260100 hasConcept C108583219 @default.
- W4292260100 hasConcept C111919701 @default.
- W4292260100 hasConcept C119857082 @default.
- W4292260100 hasConcept C124101348 @default.
- W4292260100 hasConcept C134306372 @default.
- W4292260100 hasConcept C154945302 @default.
- W4292260100 hasConcept C173801870 @default.
- W4292260100 hasConcept C177264268 @default.
- W4292260100 hasConcept C190502265 @default.
- W4292260100 hasConcept C199360897 @default.
- W4292260100 hasConcept C2776214188 @default.
- W4292260100 hasConcept C33923547 @default.
- W4292260100 hasConcept C41008148 @default.
- W4292260100 hasConcept C51632099 @default.
- W4292260100 hasConcept C58489278 @default.
- W4292260100 hasConcept C77618280 @default.
- W4292260100 hasConcept C98045186 @default.
- W4292260100 hasConceptScore W4292260100C108583219 @default.
- W4292260100 hasConceptScore W4292260100C111919701 @default.
- W4292260100 hasConceptScore W4292260100C119857082 @default.
- W4292260100 hasConceptScore W4292260100C124101348 @default.
- W4292260100 hasConceptScore W4292260100C134306372 @default.
- W4292260100 hasConceptScore W4292260100C154945302 @default.
- W4292260100 hasConceptScore W4292260100C173801870 @default.
- W4292260100 hasConceptScore W4292260100C177264268 @default.
- W4292260100 hasConceptScore W4292260100C190502265 @default.
- W4292260100 hasConceptScore W4292260100C199360897 @default.
- W4292260100 hasConceptScore W4292260100C2776214188 @default.
- W4292260100 hasConceptScore W4292260100C33923547 @default.
- W4292260100 hasConceptScore W4292260100C41008148 @default.
- W4292260100 hasConceptScore W4292260100C51632099 @default.
- W4292260100 hasConceptScore W4292260100C58489278 @default.
- W4292260100 hasConceptScore W4292260100C77618280 @default.
- W4292260100 hasConceptScore W4292260100C98045186 @default.
- W4292260100 hasIssue "11" @default.
- W4292260100 hasLocation W42922601001 @default.
- W4292260100 hasOpenAccess W4292260100 @default.
- W4292260100 hasPrimaryLocation W42922601001 @default.