DifGuard: a privacy protection mechanism for neural network classifiers
Jiang Zhao, Ping Li, Mingwei Liang, Jingjing Li · 2024
Machine learning classifier may leak sensitive information from data providers. Attackers can use an algorithm called membership inference attack (MIA) to infer whether samples have been used as training data for the classifier. To prevent MIAs, researchers have proposed various defense methods. However, these methods often struggle to balance three constraints: the trade-off between utility and privacy, the impact on prediction accuracy, and effectiveness against both NN and Metric-based MIAs. Therefore, we propose a defense strategy called DifGuard, which is based on differential privacy and uses different privacy budgets depending on data membership during the model inference phase. To validate the effectiveness of DifGuard, we conducted extensive experiments on multiple publicly available datasets. Experimental results demonstrate that, compared to the state-of-the-art defense strategies, Dif- Guard can more effectively mitigate various risks of MIA without compromising classification accuracy.