An Approximate Memory Based Defense Against Model Inversion Attacks to Neural Networks

Qian Xu, Md Tanvir Arafin, Gang Qu · IEEE Transactions on Emerging Topics in Computing · 2022

Diverse and comprehensive training data is critical in building robust machine learning (ML) models. However, model inversion attacks (MIA) have demonstrated that an ML model can leak important information about its training dataset. This work examines the existing MIAs and proposes a hardware-oriented solution to protect the training data from such attacks. Our proposed solution – MIDAS: Model Inversion Defenses with an Approximate memory System – intentionally introduces memory faults to thwart MIA without compromising the original ML model. We use detailed SPICE simulations to build the DRAM fault model with voltage overscaling, implement the state-of-the-art MIAs, and evaluate our proposed solution. Our experiments demonstrate that MIDAS can effectively protect training data from run-time adversarial attacks. In terms of the Pearson Correlation Coefficient (PCC) similarity measure (between the original and the recovered training data), MIDAS reduces the PCC value for shallow and deep neural networks.

Read the paper · More papers on PaperTik