无影成员推断攻击:推荐系统比你想象的更脆弱
摘要
推荐系统已成功应用于众多应用场景。然而,近期研究表明推荐系统对成员推断攻击(Membership Inference Attacks,简称MIAs)极其脆弱,从而导致用户成员隐私泄露。然而,现有依赖影子训练的MIAs在攻击者缺乏训练数据分布和目标推荐系统模型架构知识的情况下,性能会大幅下降。为更好地理解推荐系统的隐私风险,本文提出了无影成员推断攻击方法,直接利用用户的推荐结果进行成员推断。在没有影子训练的情况下,该攻击方法可在攻击者仅获得目标推荐系统黑盒访问权限的情况下高效有效地进行MIAs。该攻击基于一种直觉:推荐系统会针对用户的历史交互情况对其推荐进行个性化。因此,攻击者可以通过判断推荐结果是更类似于用户的交互记录还是更类似于普遍受欢迎的条目,从而推断用户的成员隐私。我们在多个基准数据集上进行了广泛实验。令人惊讶的是,尽管基准方法在计算成本上具有显著优势,本文提出的攻击在实现更低假阳性率的同时,还能实现远高于基准方法的更高攻击准确率。
引用
@article{arxiv.2405.07017,
title = {Robot Agnostic Visual Servoing considering kinematic constraints enabled by a decoupled network trajectory planner structure},
author = {Constantin Schempp and Christian Friedrich},
journal= {arXiv preprint arXiv:2405.07017},
year = {2024}
}
备注
\copyright 2024 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works