{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T02:43:29Z","timestamp":1747190609807,"version":"3.40.5"},"reference-count":43,"publisher":"Wiley","license":[{"start":{"date-parts":[[2021,6,18]],"date-time":"2021-06-18T00:00:00Z","timestamp":1623974400000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security and Communication Networks"],"published-print":{"date-parts":[[2021,6,18]]},"abstract":"<jats:p>In recent years, machine learning approaches have been widely adopted for many applications, including classification. Machine learning models deal with collective sensitive data usually trained in a remote public cloud server, for instance, machine learning as a service (MLaaS) system. In this scene, users upload their local data and utilize the computation capability to train models, or users directly access models trained by MLaaS. Unfortunately, recent works reveal that the curious server (that trains the model with users\u2019 sensitive local data and is curious to know the information about individuals) and the malicious MLaaS user (who abused to query from the MLaaS system) will cause privacy risks. The adversarial method as one of typical mitigation has been studied by several recent works. However, most of them focus on the privacy-preserving against the malicious user; in other words, they commonly consider the data owner and the model provider as one role. Under this assumption, the privacy leakage risks from the curious server are neglected. Differential privacy methods can defend against privacy threats from both the curious sever and the malicious MLaaS user by directly adding noise to the training data. Nonetheless, the differential privacy method will decrease the classification accuracy of the target model heavily. In this work, we propose a generic privacy-preserving framework based on the adversarial method to defend both the curious server and the malicious MLaaS user. The framework can adapt with several adversarial algorithms to generate adversarial examples directly with data owners\u2019 original data. By doing so, sensitive information about the original data is hidden. Then, we explore the constraint conditions of this framework which help us to find the balance between privacy protection and the model utility. The experiments\u2019 results show that our defense framework with the AdvGAN method is effective against MIA and our defense framework with the FGSM method can protect the sensitive data from direct content exposed attacks. In addition, our method can achieve better privacy and utility balance compared to the existing method.<\/jats:p>","DOI":"10.1155\/2021\/9924684","type":"journal-article","created":{"date-parts":[[2021,6,18]],"date-time":"2021-06-18T20:20:09Z","timestamp":1624047609000},"page":"1-13","source":"Crossref","is-referenced-by-count":0,"title":["A Defense Framework for Privacy Risks in Remote Machine Learning Service"],"prefix":"10.1155","volume":"2021","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2475-4232","authenticated-orcid":true,"given":"Yang","family":"Bai","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"},{"name":"No. 30, Institute of CETC, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingchuang","family":"Xie","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4784-6578","authenticated-orcid":true,"given":"Mingyu","family":"Fan","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","reference":[{"first-page":"770","article-title":"Deep residual learning for image recognition","author":"K. He","key":"1"},{"article-title":"Deep speech: scaling up end-to-end speech recognition","year":"2014","author":"A. Hannun","key":"2"},{"key":"3","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-018-0316-z"},{"author":"B. Krollner","key":"4","article-title":"Financial time series forecasting with machine learning techniques: a survey"},{"first-page":"3","article-title":"Membership inference attacks against machine learning models","author":"R. Shokri","key":"5"},{"article-title":"Logan: evaluating information leakage of generative models using generative adversarial networks","year":"2018","author":"J. Hayes","key":"6"},{"first-page":"634","article-title":"Machine learning with membership privacy using adversarial regularization","author":"M. Nasr","key":"7"},{"first-page":"259","article-title":"Memguard: defending against black-box membership inference attacks via adversarial examples","author":"J. Jia","key":"8"},{"article-title":"Mcmia: model compression against membership inference attack in deep neural networks","year":"2020","author":"Y. Wang","key":"9"},{"article-title":"Privacy in deep learning: a survey","year":"2020","author":"F. Mirshghallah","key":"10"},{"first-page":"601","article-title":"Stealing machine learning models via prediction apis","author":"F. Tram\u00e8r","key":"11"},{"first-page":"1322","article-title":"Model inversion attacks that exploit confidence information and basic countermeasures","author":"M. Fredrikson","key":"12"},{"first-page":"17","article-title":"Privacy in pharmacogenetics: an end-to-end case study of personalized warfarin dosing","author":"M. Fredrikson","key":"13"},{"article-title":"Understanding membership inferences on well-generalized learning models","year":"2018","author":"Y. Long","key":"14"},{"article-title":"Model and data independent membership inference attacks and defenses on machine learning models","year":"2018","author":"A. Salem","key":"15"},{"first-page":"1895","article-title":"Evaluating differentially private machine learning in practice","author":"B. Jayaraman","key":"16"},{"author":"L. Song","key":"17","article-title":"Systematic evaluation of privacy risks of machine learning models"},{"key":"18","first-page":"9","article-title":"On the connection between differential privacy and adversarial robustness in machine learning","volume":"1050","author":"M. Lecuyer","year":"2018","journal-title":"Stat"},{"article-title":"Towards measuring membership privacy","year":"2017","author":"Y. Long","key":"19"},{"article-title":"Weight normalization: a simple reparameterization to accelerate training of deep neural networks","year":"2016","author":"T. Salimans","key":"20"},{"issue":"1","key":"21","first-page":"1929","article-title":"Dropout: a simple way to prevent neural networks from overfitting","volume":"15","author":"N. Srivastava","year":"2014","journal-title":"The Journal of Machine Learning Research"},{"first-page":"1310","article-title":"Privacy-preserving deep learning","author":"R. Shokri","key":"22"},{"first-page":"1","article-title":"Differential privacy: a survey of results","author":"C. Dwork","key":"23"},{"first-page":"371","article-title":"Differential privacy and robust statistics","author":"C. Dwork","key":"24"},{"key":"25","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"first-page":"51","article-title":"Boosting and differential privacy","author":"C. Dwork","key":"26"},{"issue":"3-4","key":"27","first-page":"211","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"C. D, work","year":"2014","journal-title":"Foundations and Trends\u00ae in Theoretical Computer Science"},{"article-title":"Differential privacy defenses and sampling attacks for membership inference","author":"S. Rahimian","key":"28","doi-asserted-by":"crossref","DOI":"10.1145\/3474369.3486876"},{"article-title":"Generating differentially private datasets using gans","year":"2018","author":"A. Triastcyn","key":"29"},{"article-title":"Semi-supervised knowledge transfer for deep learning from private training data","year":"2016","author":"N. Papernot","key":"30"},{"article-title":"The secret sharer: measuring unintended neural network memorization & extracting secrets","year":"2018","author":"N. Carlini","key":"31"},{"article-title":"Defending model inversion and membership inference attacks via prediction purification","year":"2020","author":"Z. Yang","key":"32"},{"first-page":"39","article-title":"Towards Evaluating the Robustness of Neural Networks","author":"N. Carlini","key":"33"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"I. J. Goodfellow","key":"34"},{"article-title":"Adversarial examples in the physical world","year":"2016","author":"A. Kurakin","key":"35"},{"article-title":"Towards deep learning models resistant to adversarial attacks","year":"2017","author":"A. Madry","key":"36"},{"first-page":"1765","article-title":"Universal adversarial perturbations","author":"S.-M. Moosavi-Dezfooli","key":"37"},{"first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"S.-M. Moosavi-Dezfooli","key":"38"},{"first-page":"372","article-title":"The limitations of deep learning in adversarial settings","author":"N. Papernot","key":"39"},{"article-title":"Generating natural adversarial examples","year":"2017","author":"Z. Zhao","key":"40"},{"article-title":"Generating adversarial examples with adversarial networks","year":"2018","author":"C. Xiao","key":"41"},{"author":"W. He","key":"42","article-title":"Decision boundary analysis of adversarial examples"},{"article-title":"The MNIST database of handwritten digits","year":"1998","author":"Y. LeCun","key":"43"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/9924684.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/9924684.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/scn\/2021\/9924684.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,31]],"date-time":"2022-12-31T18:03:19Z","timestamp":1672509799000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/scn\/2021\/9924684\/"}},"subtitle":[],"editor":[{"given":"Jiang","family":"Ming","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2021,6,18]]},"references-count":43,"alternative-id":["9924684","9924684"],"URL":"https:\/\/doi.org\/10.1155\/2021\/9924684","relation":{},"ISSN":["1939-0122","1939-0114"],"issn-type":[{"type":"electronic","value":"1939-0122"},{"type":"print","value":"1939-0114"}],"subject":[],"published":{"date-parts":[[2021,6,18]]}}}