|国家预印本平台
首页|DynaNoise: Dynamic Probabilistic Noise Injection for Defending Against Membership Inference Attacks

DynaNoise: Dynamic Probabilistic Noise Injection for Defending Against Membership Inference Attacks

DynaNoise: Dynamic Probabilistic Noise Injection for Defending Against Membership Inference Attacks

来源:Arxiv_logoArxiv
英文摘要

Membership Inference Attacks (MIAs) pose a significant risk to the privacy of training datasets by exploiting subtle differences in model outputs to determine whether a particular data sample was used during training. These attacks can compromise sensitive information, especially in domains such as healthcare and finance, where data privacy is paramount. Traditional mitigation techniques, such as static differential privacy, rely on injecting a fixed amount of noise during training or inference. However, this approach often leads to a detrimental trade-off: the noise may be insufficient to counter sophisticated attacks or, when increased, may substantially degrade model performance. In this paper, we present DynaNoise, an adaptive approach that dynamically modulates noise injection based on query sensitivity. Our approach performs sensitivity analysis using measures such as Shannon entropy to evaluate the risk associated with each query and adjusts the noise variance accordingly. A probabilistic smoothing step is then applied to renormalize the perturbed outputs, ensuring that the model maintains high accuracy while effectively obfuscating membership signals. We further propose an empirical metric, the Membership Inference Defense Privacy-Utility Tradeoff (MIDPUT), which quantifies the balance between reducing attack success rates and preserving the target model's accuracy. Our extensive evaluation on several benchmark datasets demonstrates that DynaNoise not only significantly reduces MIA success rates but also achieves up to a fourfold improvement in the MIDPUT metric compared to the state-of-the-art. Moreover, DynaNoise maintains competitive model accuracy while imposing only marginal inference overhead, highlighting its potential as an effective and efficient privacy defense against MIAs.

Javad Forough、Hamed Haddadi

计算技术、计算机技术

Javad Forough,Hamed Haddadi.DynaNoise: Dynamic Probabilistic Noise Injection for Defending Against Membership Inference Attacks[EB/OL].(2025-05-19)[2025-06-29].https://arxiv.org/abs/2505.13362.点此复制

评论