{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T02:54:14Z","timestamp":1760237654892,"version":"build-2065373602"},"reference-count":35,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T00:00:00Z","timestamp":1658275200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001665","name":"ANR (Agence Nationale de la Recherche, National Agency for Research)","doi-asserted-by":"publisher","award":["ANR-19-CHIA-0022"],"award-info":[{"award-number":["ANR-19-CHIA-0022"]}],"id":[{"id":"10.13039\/501100001665","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>We address the problem of defending predictive models, such as machine learning classifiers (Defender models), against membership inference attacks, in both the black-box and white-box setting, when the trainer and the trained model are publicly released. The Defender aims at optimizing a dual objective: utility and privacy. Privacy is evaluated with the membership prediction error of a so-called \u201cLeave-Two-Unlabeled\u201d LTU Attacker, having access to all of the Defender and Reserved data, except for the membership label of one sample from each, giving the strongest possible attack scenario. We prove that, under certain conditions, even a \u201cna\u00efve\u201d LTU Attacker can achieve lower bounds on privacy loss with simple attack strategies, leading to concrete necessary conditions to protect privacy, including: preventing over-fitting and adding some amount of randomness. This attack is straightforward to implement against any model trainer, and we demonstrate its performance against MemGaurd. However, we also show that such a na\u00efve LTU Attacker can fail to attack the privacy of models known to be vulnerable in the literature, demonstrating that knowledge must be complemented with strong attack strategies to turn the LTU Attacker into a powerful means of evaluating privacy. The LTU Attacker can incorporate any existing attack strategy to compute individual privacy scores for each training sample. Our experiments on the QMNIST, CIFAR-10, and Location-30 datasets validate our theoretical results and confirm the roles of over-fitting prevention and randomness in the algorithms to protect against privacy attacks.<\/jats:p>","DOI":"10.3390\/a15070254","type":"journal-article","created":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T11:22:24Z","timestamp":1658316144000},"page":"254","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["LTU Attacker for Membership Inference"],"prefix":"10.3390","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6223-9848","authenticated-orcid":false,"given":"Joseph","family":"Pedersen","sequence":"first","affiliation":[{"name":"Department of Industrial and Systems Engineering, Rensselaer Polytechnic Institute, Troy, NY 12180, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4890-5605","authenticated-orcid":false,"given":"Rafael","family":"Mu\u00f1oz-G\u00f3mez","sequence":"additional","affiliation":[{"name":"LISN\/CNRS\/INRIA, Paris-Saclay University, 3 Rue Joliot Curie B\u00e2timent Breguet, 91190 Gif-sur-Yvette, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiangnan","family":"Huang","sequence":"additional","affiliation":[{"name":"LISN\/CNRS\/INRIA, Paris-Saclay University, 3 Rue Joliot Curie B\u00e2timent Breguet, 91190 Gif-sur-Yvette, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haozhe","family":"Sun","sequence":"additional","affiliation":[{"name":"LISN\/CNRS\/INRIA, Paris-Saclay University, 3 Rue Joliot Curie B\u00e2timent Breguet, 91190 Gif-sur-Yvette, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei-Wei","family":"Tu","sequence":"additional","affiliation":[{"name":"4Paradigm, 66 Qinghe Middle Street, Beijing 100089, China"},{"name":"ChaLearn, 397 Schimke Road, Alpine County, CA 95223, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9266-1783","authenticated-orcid":false,"given":"Isabelle","family":"Guyon","sequence":"additional","affiliation":[{"name":"LISN\/CNRS\/INRIA, Paris-Saclay University, 3 Rue Joliot Curie B\u00e2timent Breguet, 91190 Gif-sur-Yvette, France"},{"name":"ChaLearn, 397 Schimke Road, Alpine County, CA 95223, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,7,20]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2019, January 19\u201323). Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00065"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., and Shmatikov, V. (2017, January 22\u201324). Membership inference attacks against machine learning models. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.41"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Li, N., Qardaji, W., Su, D., Wu, Y., and Yang, W. (2013, January 4\u20138). Membership privacy: A unifying framework for privacy definitions. Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, Berlin, Germany.","DOI":"10.1145\/2508859.2516686"},{"key":"ref_4","unstructured":"Long, Y., Bindschaedler, V., and Gunter, C.A. (2017). Towards measuring membership privacy. arXiv."},{"key":"ref_5","unstructured":"Thudi, A., Shumailov, I., Boenisch, F., and Papernot, N. (2022). Bounding Membership Inference. arXiv."},{"key":"ref_6","unstructured":"Song, L., and Mittal, P. (2021, January 11\u201313). Systematic evaluation of privacy risks of machine learning models. Proceedings of the 30th {USENIX} Security Symposium ({USENIX} Security 21), Virtual Event."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Jayaraman, B., Wang, L., Knipmeyer, K., Gu, Q., and Evans, D. (2020). Revisiting membership inference under realistic assumptions. arXiv.","DOI":"10.2478\/popets-2021-0031"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., and Jha, S. (2018, January 9\u201312). Privacy risk in machine learning: Analyzing the connection to overfitting. Proceedings of the 2018 IEEE 31st Computer Security Foundations Symposium (CSF), Oxford, UK.","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"2073","DOI":"10.1109\/TSC.2019.2897554","article-title":"Demystifying membership inference attacks in machine learning as a service","volume":"14","author":"Truex","year":"2019","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Hayes, J., Melis, L., Danezis, G., and Cristofaro, E.D. (2018). LOGAN: Membership Inference Attacks Against Generative Models. arXiv.","DOI":"10.2478\/popets-2019-0008"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Hilprecht, B., H\u00e4rterich, M., and Bernau, D. (2019). Reconstruction and Membership Inference Attacks against Generative Models. arXiv.","DOI":"10.2478\/popets-2019-0067"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Chen, D., Yu, N., Zhang, Y., and Fritz, M. (2020, January 9\u201313). Gan-leaks: A taxonomy of membership inference attacks against generative models. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event.","DOI":"10.1145\/3372297.3417238"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. Theory of Cryptography Conference, Springer.","DOI":"10.1007\/11681878_14"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Abadi, M., Chu, A., Goodfellow, I., McMahan, H.B., Mironov, I., Talwar, K., and Zhang, L. (2016, January 24\u201328). Deep learning with differential privacy. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978318"},{"key":"ref_15","unstructured":"Xie, L., Lin, K., Wang, S., Wang, F., and Zhou, J. (2018). Differentially private generative adversarial network. arXiv."},{"key":"ref_16","first-page":"2030","article-title":"Domain-adversarial training of neural networks","volume":"17","author":"Ganin","year":"2016","journal-title":"J. Mach. Learn. Res."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2018, January 15\u201319). Machine learning with membership privacy using adversarial regularization. Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada.","DOI":"10.1145\/3243734.3243855"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Huang, H., Luo, W., Zeng, G., Weng, J., Zhang, Y., and Yang, A. (2021). DAMIA: Leveraging Domain Adaptation as a Defense against Membership Inference Attacks. IEEE Trans. Dependable Secur. Comput.","DOI":"10.1109\/TDSC.2021.3088480"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Nasr, M., Song, S., Thakurta, A., Papernot, N., and Carlini, N. (2021, January 24\u201327). Adversary Instantiation: Lower Bounds for Differentially Private Machine Learning. Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP40001.2021.00069"},{"key":"ref_20","unstructured":"Sablayrolles, A., Douze, M., Schmid, C., Ollivier, Y., and J\u00e9gou, H. (2019, January 9\u201315). White-box vs black-box: Bayes optimal strategies for membership inference. Proceedings of the International Conference on Machine Learning, PMLR, Long Beach, CA, USA."},{"key":"ref_21","unstructured":"Liu, X., Xu, Y., Tople, S., Mukherjee, S., and Ferres, J.L. (2020). Mace: A flexible framework for membership privacy estimation in generative models. arXiv."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"52","DOI":"10.1109\/34.655649","article-title":"What size test set gives good error rate estimates?","volume":"20","author":"Guyon","year":"1998","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"17","DOI":"10.29012\/jpc.v7i3.405","article-title":"Calibrating Noise to Sensitivity in Private Data Analysis","volume":"7","author":"Dwork","year":"2017","journal-title":"J. Priv. Confidentiality"},{"key":"ref_24","unstructured":"Krizhevsky, A. (2009). Learning Multiple Layers of Features from Tiny Images, University of Toronto. Technical Report TR-2009."},{"key":"ref_25","unstructured":"Yadav, C., and Bottou, L. (2019). Cold Case: The Lost MNIST Digits. Advances in Neural Information Processing Systems 32, Curran Associates, Inc."},{"key":"ref_26","first-page":"61","article-title":"Membership Inference Attack against Differentially Private Deep Learning Model","volume":"11","author":"Rahman","year":"2018","journal-title":"Trans. Data Priv."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"LeCun","year":"1998","journal-title":"Proc. IEEE"},{"key":"ref_28","unstructured":"Simonyan, K., and Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., and Fei-Fei, L. (2009, January 20\u201325). Imagenet: A large-scale hierarchical image database. Proceedings of the 2009 IEEE Conference on Computer Vision and Pattern Recognition, Miami, FL, USA.","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref_30","unstructured":"Tan, M., and Le, Q.V. (2021). Efficientnetv2: Smaller models and faster training. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Jia, J., Salem, A., Backes, M., Zhang, Y., and Gong, N.Z. (2019). MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples, Association for Computing Machinery. CCS\u201919.","DOI":"10.1145\/3319535.3363201"},{"key":"ref_32","unstructured":"Wang, J., and Hou, W. (2022, May 04). DeepDA: Deep Domain Adaptation Toolkit. Available online: https:\/\/github.com\/jindongwang\/transferlearning\/tree\/master\/code\/DeepDA."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_34","unstructured":"Sun, H., Tu, W.W., and Guyon, I.M. (2022). OmniPrint: A Configurable Printed Character Synthesizer. arXiv."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1713","DOI":"10.1109\/TNNLS.2020.2988928","article-title":"Deep Subdomain Adaptation Network for Image Classification","volume":"32","author":"Zhu","year":"2021","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-4893\/15\/7\/254\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:55:02Z","timestamp":1760140502000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-4893\/15\/7\/254"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,20]]},"references-count":35,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2022,7]]}},"alternative-id":["a15070254"],"URL":"https:\/\/doi.org\/10.3390\/a15070254","relation":{},"ISSN":["1999-4893"],"issn-type":[{"type":"electronic","value":"1999-4893"}],"subject":[],"published":{"date-parts":[[2022,7,20]]}}}