Assessing Membership Leakages Via Task-Aligned Divergent Shadow Datasets in Vehicular Road Cooperation

Pengrui Liu,Wei Wang,Xiangrui Xu,Hanxi Li,Weiping Ding
DOI: https://doi.org/10.1109/jiot.2024.3380642
IF: 10.6
2024-01-01
IEEE Internet of Things Journal
Abstract:Deep classification models have been widely utilized in Vehicular Road Cooperation. However, previous work indicates that deep classification models are vulnerable to the privacy risks of Membership Inference Attacks (MIAs). Most existing work of MIAs is based on two different assumptions. One assumes adversary-own shadow datasets with aligned tasks and distributions as private datasets, while this assumption necessitates that the adversary knows the distributions of private datasets. The other assumes adversary-own shadow datasets with distinct tasks and distributions from private datasets, while this assumption requires that the adversary knows the classification boundaries between members and non-members of the private dataset. Hence, these two assumptions do not always hold in real-world scenarios. In this work, we systematically assess the impact of adversaryown shadow datasets with aligned tasks but distinct distributions from private datasets on MIAs. These realistic shadow datasets acknowledge adversaries limited insights into the data distribution of the private dataset and the decision boundary between members and non-members. We divide these practical shadow datasets hosted by adversaries into 4 types: Data Noise, Label Noise, Imbalanced Data, and Cross-domain Data. We conduct extensive experiments with 7 prevalent MIAs and 4 types of shadow datasets. Experimental results mainly reveal two-fold findings. First, MIAs still maintain effectiveness using the shadow dataset with the aligned task but distinct distributions from the private dataset. Second, different levels of data distribution disparities manifest varying MIAs’ performances under certain types of shadow datasets.
What problem does this paper attempt to address?