Artificial Intelligence Security and Privacy Protection: A Defense Strategy for Machine Learning Models
Yu Xue · 2024
The demand for AI security and privacy has been growing. It is necessary to innovate in ways and technologies for reducing the privacy leakage rate. This chapter proposes a defense strategy from the perspective of the machine learning model itself to prevent anti-attack risk and privacy leakage risk. Based on the comprehensive study of the existing research, this chapter discusses the key defense strategies for machine learning models, including confrontation training, model distillation, input space restriction, and model repair. In addition, it also talks about the application of differential privacy technology, data desensitization, and access control strategies in privacy protection. Finally, the chapter evaluates the privacy leakage rate of algorithms, and the results show that it is between 1% and 1.8%. Among these methods, the defense strategy of confrontation training has a relatively good performance, and introducing confrontation samples can make the robustness of the model significantly improved.