Universal and Efficient Adversarial Training Framework With Membership Inference Resistance

Ran Yan, Ruiying Du, Kun He, Jing Chen, Qiao Li, Cong Wu · IEEE Internet of Things Journal · 2025

Adversarial training is an effective approach to enhance the robustness of machine learning models via adding adversarial examples into the training phase. However, existing adversarial training methods increase the advantage of membership inference attacks, which aim to determine from the model whether an example is in the training dataset. In this article, we propose an adversarial training framework that guarantees both robustness and membership privacy by introducing a tailor-made example called reverse-symmetry example. Moreover, our framework reduces the number of required adversarial examples compared with existing adversarial training methods. We implement our framework using four adversarial training methods on the FMNIST and CIFAR10 datasets and compare its performance with deep learning differential privacy. Our experimental findings demonstrate that our framework mitigates model overfitting and outperforms the original adversarial training with respect to the overall performance of accuracy, robustness, privacy, and runtime.

Read the paper · More papers on PaperTik