Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

An Optimal Knowledge Distillation for Formulating an Effective Defense Model Against Membership Inference Attacks

Author 1: Thi Thanh Thuy Pham Author 2: Huong-Giang Doan
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 15, No. 5 · Published 2024

DOI: https://doi.org/10.14569/IJACSA.2024.01505140

Abstract

A membership inference attack (MIA) on machine learning models aims to determine the sensitive data that has been used to train machine learning models. Machine learning-based applications (MLaaS—machine learning as a service) in finance, banking, healthcare, etc. are facing the risks of private data leaks by MIA. Several solutions have been proposed for mitigating MIA attacks, such as confidence score masking, regularization, knowledge distillation (KD), etc. However, the utility-privacy trade-off problem is still a major challenge for existing approaches. In this work, we explore the KD-based approach to defending against MIA attacks. This approach has received increasing attention in the research community on machine learning safety recently as it aims at effectively addressing the above-mentioned challenge of mitigating MIA attacks. An efficient KD-based defense framework that includes multiple teacher and student models is proposed in this work for alleviating MIA attacks. Three main phases are deployed in this framework: (1) teacher model training; (2) knowledge distillation from the teacher model to the student model based on prediction augmentation and aggregation from the teacher model; and (3) repeated knowledge distillation among student models. The experimental results on standard datasets show the outperforms in both model utility and privacy of the proposed framework compared to other state-of-the-art solutions for mitigating MIA.

Keywords

How to Cite this Article

Pham, T. T. T., & Doan, H. (2024). An Optimal Knowledge Distillation for Formulating an Effective Defense Model Against Membership Inference Attacks. International Journal of Advanced Computer Science and Applications, 15(5). https://doi.org/10.14569/IJACSA.2024.01505140

Pham, Thi Thanh Thuy, and Huong-Giang Doan. "An Optimal Knowledge Distillation for Formulating an Effective Defense Model Against Membership Inference Attacks." International Journal of Advanced Computer Science and Applications, vol. 15, no. 5, 2024, https://doi.org/10.14569/IJACSA.2024.01505140.

@article{Pham2024,
  title     = {An Optimal Knowledge Distillation for Formulating an Effective Defense Model Against Membership Inference Attacks},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {15},
  number    = {5},
  year      = {2024},
  publisher = {The Science and Information Organization},
  author    = {Thi Thanh Thuy Pham and Huong-Giang Doan},
  doi       = {10.14569/IJACSA.2024.01505140},
  url       = {https://doi.org/10.14569/IJACSA.2024.01505140}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.