Pith. sign in

REVIEW 1 cited by

Defending Model Inversion and Membership Inference Attacks via Prediction Purification

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2005.03915 v2 pith:BD4K44KA submitted 2020-05-08 cs.CR cs.LG

classification cs.CRcs.LG
keywords attacksinferenceattackmembershipconfidencedatainversionmodel
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Neural networks are susceptible to data inference attacks such as the model inversion attack and the membership inference attack, where the attacker could infer the reconstruction and the membership of a data sample from the confidence scores predicted by the target classifier. In this paper, we propose a unified approach, namely purification framework, to defend data inference attacks. It purifies the confidence score vectors predicted by the target classifier by reducing their dispersion. The purifier can be further specialized in defending a particular attack via adversarial learning. We evaluate our approach on benchmark datasets and classifiers. We show that when the purifier is dedicated to one attack, it naturally defends the other one, which empirically demonstrates the connection between the two attacks. The purifier can effectively defend both attacks. For example, it can reduce the membership inference accuracy by up to 15% and increase the model inversion error by a factor of up to 4. Besides, it incurs less than 0.4% classification accuracy drop and less than 5.5% distortion to the confidence scores.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. LoMime: Query-Efficient Membership Inference using Model Extraction in Label-Only Settings

    cs.LG 2026-02 conditional novelty 5.0 of 10

    Extracting a surrogate model from a label-only API lets an attacker perform membership inference offline, matching direct-attack accuracy with a query budget of roughly 1% of the training data.

Pith tools