Bangladesh University of Engineering and Technology
被引用0|浏览0
摘要
In a model inversion attack, an adversary tries to reconstruct private training data through iterative inference of a neural network model. To ensure confidentiality of the training data, protection against model inversion attacks is crucial. However, existing defense techniques primarily require modifications to the trained model architecture or even retraining, which limits their applicability to deployed models. In addition, most of them become ineffective against label-only attacks, which require minimal information to succeed. This paper proposes an improved defense mechanism that filters out inference requests from malicious attackers. It does not alter existing model architectures and works against various types of attacks. Our experimental results show that our approach is highly effective with mean defense accuracy scores of 90.00
更多
查看译文
关键词
Model inversion attack,ML privacy,Label-only attack,Server-side defense,ML attacks,Input reconstruction