Member privacy security assessment method for capsule network
Through the member privacy security assessment method for the capsule network, technical means such as preprocessing data sets and building shadow models, the privacy leakage problem of the capsule network when facing member reasoning attacks is solved, and effective security assessment and privacy protection are achieved.
Patent Information
- Application Number
- CN202510296547.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-17
AI Technical Summary
When faced with member reasoning attacks, the capsule network lacks effective security assessment and defense mechanisms, resulting in potential privacy leakage problems.
A method for member privacy security assessment of capsule networks is proposed, by preprocessing the data set, building shadow models and capsule network models, building attack data sets and attack test data sets, and training attack models to verify the security of capsule network models.
It effectively realizes security assessment and privacy protection of capsule networks, reduces the success rate of member inference attacks, and ensures the security of the model when facing attacks.
Smart Images

Figure CN120165918A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of network security and artificial intelligence, focuses on privacy protection and security evaluation of machine learning models, and particularly relates to a method for evaluating the membership privacy security of capsule networks. Background Art
[0002] In 2017, Hinton first proposed the concept of Capsule Network (CapsNet) and speculated that this model might become the next-generation neural network architecture. Through a dynamic routing mechanism, CapsNet enables the effective transfer of information from low-level capsules to high-level capsules, thus significantly enhancing the feature extraction ability. As an innovative neural network structure, CapsNet has demonstrated excellent performance in multiple visual recognition tasks. Therefore, many researchers in the medical field have started to introduce CapsNet and conduct in-depth research, such as using CapsNet for automatic disease classification, re-identifying leukemia in blood smear images, and using CapsNet for medical diagnosis, etc. However, regarding the security of CapsNet, especially its defense ability against membership inference attacks, the academic community has not conducted systematic exploration. Given the wide application of CapsNet in multiple fields, if the model based on CapsNet is attacked, it may lead to serious privacy leakage problems.
[0003] Membership Inference Attack (MIA) is a concept proposed by Shokri et al. in 2017. This attack method allows an attacker to infer the training dataset information of a machine learning model through specific technical means. Membership inference attacks are divided into two types: those oriented towards federated learning and those oriented towards traditional machine learning. In the membership inference attack oriented towards machine learning, the attacker infers whether specific data belongs to the training set of the model based on the output results of the model for this data. The core principle is that machine learning models often overfit to the training set data, so they will show higher prediction confidence for the data in the training set. This attack is particularly important in terms of privacy protection, especially in scenarios involving sensitive personal data, such as biomedical data and mobile tracking data, where it may lead to serious privacy leakage problems. To defend against membership inference attacks, common strategies include techniques such as differential privacy, model pruning, and knowledge distillation.
[0004] Although CapsNet has demonstrated excellent performance in fields such as feature extraction and image recognition, it still faces numerous challenges in terms of security and privacy protection. Especially in the research field of dealing with membership inference attacks, it is currently in the initial exploration stage, and there are relatively few relevant research results. Summary of the Invention
[0005] The present invention is a defense mechanism against membership inference attacks, and proposes a method for evaluating the membership privacy security of capsule networks, realizing the security evaluation of capsule networks and protecting security and privacy.
[0006] A method for evaluating the membership privacy security of a capsule network includes: Preprocess the FashionMNIST dataset and the CIFAR10 dataset, and train the constructed shadow model and capsule network model based on the preprocessed datasets; Construct an attack dataset and an attack test dataset using the trained shadow model and capsule network model; Train an attack model using the attack dataset; Verify the security of the capsule network model using the attack test dataset.
[0007] Furthermore, the method for preprocessing the FashionMNIST dataset and the CIFAR10 dataset is as follows: modify the image sizes of the FashionMNIST dataset and the CIFAR10 dataset to fit the input of the machine learning model; divide the processed datasets into target training datasets, target test datasets, shadow training datasets, and shadow test datasets according to the ratio of 3:1:3:1.
[0008] Furthermore, construct a shadow model based on the LeNet, VGG16, and ResNet18 networks pre-trained on the Pytorch framework, and construct a capsule network model based on the CapsNet network under the open-source library framework.
[0009] Furthermore, train the shadow network and the capsule network model using the shadow training dataset and the target training dataset respectively; in the training, the Adam algorithm is used as the optimization algorithm, the single batch is set to 64, the number of training epochs is set to 100, the initial learning rate is set to 0.01, and the learning rate adjustment algorithm is the cosine annealing algorithm.
[0010] Furthermore, the construction method of the attack dataset is as follows: use the trained shadow model to predict the confidence prediction vectors of part of the shadow training dataset and all of the shadow test dataset respectively, collect all the predicted confidence prediction vectors as the attack dataset, and at the same time, set the confidence prediction vectors corresponding to the predicted part of the shadow training dataset with label 1, and set the confidence prediction vectors corresponding to the predicted shadow test dataset with label 0.
[0011] Further, the construction method of the attack test data set is as follows: Use the trained capsule network model to predict the confidence prediction vectors of part of the target training data set and all of the target test data set respectively, and collect all the confidence prediction vectors as the attack test data set. At the same time, set the label 1 for the corresponding confidence prediction vectors in the target training data set, and set the label 0 for the corresponding confidence prediction vectors in the target test data set.
[0012] Further, the method for training the attack model F using the attack data set is as follows: Build a binary classification model based on the Pytorch framework as the attack model F, and use the attack data set to train the attack model F; The optimization algorithm in training the attack model F adopts the Adam algorithm, the single batch is set to 64, the number of training epochs is set to 100, the initial learning rate is set to 0.01, and the learning rate adjustment algorithm is the cosine annealing algorithm.
[0013] Further, the implementation of the capsule network model includes the following three steps: Step 1: Convolutional layer Input the image into a convolutional kernel with a dimension of 256 and a stride of 1, and use the ReLU activation function; If the data set used is the CIFAR10 data set, then two additional convolutional kernels without padding are added to the first layer, and finally a tensor is output; Step 2: PrimaryCaps layer After passing through the convolutional layer, input the tensor data into 8 convolutional kernels with a stride of 2, where 256 is split into 32 capsules, and finally a tensor is output; Step 3: DigitCaps layer After passing through the PrimaryCaps layer, input the tensor data into the DigitCaps layer, and output a final output.
[0014] The beneficial effects of the present invention are as follows: According to the characteristics of membership inference attacks for machine learning, the present invention specifically involves a set of methods for evaluating the security of capsule networks, effectively realizing the protection of security and privacy. Description of the Drawings
[0015] Figure 1 It is a flowchart of the experimental design of a method for evaluating the membership privacy security of a capsule network according to the present invention. Detailed Embodiments
[0016] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0017] Figure 1 This is the experimental design flowchart of a method for evaluating the member privacy security of a capsule network according to the present invention. Specifically, a method for evaluating the member privacy security of a capsule network is an evaluation method related to the characteristics of membership inference attacks for machine learning.
[0018] Membership Inference Attack is a privacy attack method against machine learning models. It infers whether specific data has been used in the training set of the model by analyzing the output behavior of the model. This type of attack reveals the potential association between the data and the training set by comparing the response differences of the model to the target data and other data, thus potentially violating data privacy.
[0019] To reduce or avoid the response differences of the model to the target data and other data, the following method for evaluating the member privacy security of a capsule network is involved, which specifically includes the following steps: Step 1: Data preprocessing Modify the image sizes of the FashionMNIST dataset and the CIFAR10 dataset to fit the input of the machine learning model, and divide the processed datasets into target training datasets, target test datasets, shadow training datasets, and shadow test datasets according to the ratio of 3:1:3:1. Step 2: Model construction Build LeNet, VGG16, and ResNet18 networks pre-trained based on the Pytorch framework as shadow models, and build a CapsNet network based on the open-source library framework as the capsule network model. Step 3: Shadow model and capsule network model Use the shadow training dataset and the target training dataset divided in Step 1 to train the shadow network and the capsule network model respectively; the training optimization algorithm for the shadow model and the capsule network model adopts the Adam algorithm, the single batch is set to 64, the number of training epochs is set to 100, the initial learning rate is set to 0.01, and the learning rate adjustment algorithm is the cosine annealing algorithm. Step 4: Attack dataset construction Use the trained shadow models to predict the confidence prediction vectors of part of the shadow training dataset and the entire shadow test dataset respectively. Collect all the predicted confidence prediction vectors as the attack dataset. At the same time, set the label 1 for the confidence prediction vectors corresponding to the predicted part of the shadow training dataset, and set the label 0 for the confidence prediction vectors corresponding to the predicted shadow test dataset; Use the trained capsule network model to predict the confidence prediction vectors of part of the target training dataset and the entire target test dataset respectively, and collect all the confidence prediction vectors as the attack test dataset. At the same time, set the label 1 for the confidence prediction vectors corresponding to the target training dataset, and set the label 0 for the confidence prediction vectors corresponding to the target test dataset; Step 5: Train the attack model Build a binary classification model based on the Pytorch framework as the attack model F, and use the attack dataset to train the attack model; in the training of the attack model, the optimization algorithm uses the Adam algorithm, the single batch is set to 64, the number of training epochs is set to 100, the initial learning rate is set to 0.01, and the learning rate adjustment algorithm is the cosine annealing algorithm; Step 6: Verify the model effect After the attack model is trained, judge whether the target input is the training set data according to the input confidence prediction vector, and use the attack test dataset for performance testing.
[0020] The capsule network (CapsNet) described in the present invention is an innovative neural network architecture. It encodes the spatial combination and pose relationship of features through capsule units. Multiple capsule units use a dynamic routing algorithm to focus on the protection and transmission of important features, while suppressing irrelevant information to enhance the network's recognition ability and adaptability to image transformation. The implementation of the capsule network model includes the following three steps: Step 1: Convolutional layer Input the picture into a convolutional kernel with a dimension of 256 and a stride of 1, and use the ReLU activation function; if the dataset used is the CIFAR10 dataset, then two additional convolutional kernels without padding are added to the first layer, and finally a tensor is output; Step 2: PrimaryCaps layer After passing through the convolutional layer, input the tensor data into 8 convolutional kernels with a stride of 2, where 256 is split into 32 capsules, and finally a tensor is output; Step 3: DigitCaps layer After passing through the PrimaryCaps layer, input the tensor data into the DigitCaps layer, and output a final output.
[0021] The evaluation standard features used in the present invention are as follows: The Recall value is used to evaluate the attack performance of the membership inference attack. The formula for calculating the Recall value is as follows: The content to be evaluated is as follows: The Dropout layer, whose main function is to randomly deactivate a certain proportion of neurons during the neural network training process. Since the structure of the network is dynamically changing during each training, the network reduces its dependence on any specific training sample, thereby enhancing the generalization ability of the model and effectively reducing the risk of overfitting of the model.
[0022] Differential Privacy, by introducing random noise in the output of data queries, ensures that the impact of the addition or removal of a single data record on the statistical characteristics of the query result is limited. Specifically, based on a predetermined privacy protection parameter ε, the algorithm adds random noise that satisfies a specific distribution to the result of the data query, thereby ensuring that personal privacy is not leaked.
[0023] The technical solution of the present invention explores the security of the capsule network, especially the defense mechanism against membership inference attacks, laying a foundation for subsequent in-depth research. The application effect of differential privacy technology on the capsule network is verified through experiments, providing an empirical reference for the security defense of the capsule network. The influence of factors such as the number of shadow models and the degree of overfitting on the attack effect is analyzed, providing a reference basis for constructing a more secure capsule network model. The research results of the present invention contribute to promoting the technical improvement of the capsule network in terms of security and privacy protection, enabling it to be more securely applied in various fields.
[0024] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A member privacy security assessment method for capsule networks, characterized by: The member privacy security assessment method includes: Preprocess the FashionMNIST dataset and CIFAR10 dataset, and train the built shadow model and capsule network model based on the preprocessed dataset; Use the trained shadow model and capsule network model to build attack datasets and attack test datasets; Using the attack data set to train an attack model; The security of the capsule network model is verified using the attack test dataset.
2. A member privacy security assessment method for capsule networks according to claim 1, characterized in that: The method for preprocessing the FashionMNIST dataset and the CIFAR10 dataset is as follows: modifying the image sizes of the FashionMNIST dataset and the CIFAR10 dataset to adapt to the input of the machine learning model; and using the processed datasets as the target training dataset, the target test dataset, the shadow training dataset, and the shadow test dataset in a ratio of 3:1:3:
1.
3. A member privacy security assessment method for capsule networks as claimed in claim 1, characterized in that: The shadow model is built based on the LeNet, VGG16 and ResNet18 networks pre-trained based on the Pytorch framework, and the capsule network model is built based on the CapsNet network under the open source library framework.
4. A member privacy security assessment method for capsule networks as described in claims 2 and 3, characterized in that: Using the shadow training data set and the target training data set to train the shadow network and the capsule network model respectively; The optimization algorithm used in training is the Adam algorithm, the single batch is set to 64, the number of training rounds is set to 100, the initial learning rate is set to 0.01, and the learning rate adjustment algorithm is the cosine annealing algorithm.
5. A member privacy security assessment method for capsule networks as described in claims 1 and 4, characterized in that: The attack data set is constructed as follows: use the trained shadow model to predict the confidence prediction vectors of part of the shadow training data set and the entire shadow test data set respectively, collect all the predicted confidence prediction vectors as the attack data set, and at the same time, set the label 1 for the confidence prediction vector corresponding to the predicted part of the shadow training data set, and set the label 0 for the confidence prediction vector corresponding to the predicted shadow test data set.
6. A member privacy security assessment method for capsule networks as described in claims 1 and 4, characterized in that: The attack test data set is constructed as follows: the trained capsule network model is used to predict the confidence prediction vectors of part of the target training data set and the entire target test data set respectively, and all the confidence prediction vectors collected are used as the attack test data set. At the same time, the corresponding confidence prediction vector in the target training data set is set with a label of 1, and the corresponding confidence prediction vector in the target test data set is set with a label of 0.
7. A method for assessing member privacy security in a capsule network as claimed in claim 5, characterized in that: The method of training the attack model F using the attack data set is as follows: building a binary classification model based on the Pytorch framework as the attack model F, and using the attack data set to train the attack model F; the optimization algorithm in training the attack model F adopts the Adam algorithm, the single batch is set to 64, the number of training rounds is set to 100, the initial learning rate is set to 0.01, and the learning rate adjustment algorithm is the cosine annealing algorithm.
8. A member privacy security assessment method for capsule networks as claimed in claim 1, characterized in that: The implementation of the capsule network model includes the following three steps: Step 1: Convolutional Layer Input the image into a convolution kernel with a dimension of 256 and a stride of 1, and use the ReLU activation function; if the dataset used is the CIFAR10 dataset, add two additional convolution kernels without padding to the first layer, and finally output a tensor; Step 2: PrimaryCaps layer After the convolution layer, the tensor data is input into 8 convolution kernels with a step size of 2, where 256 are split into 32 capsules, and finally a tensor is output; Step 3: DigitCaps layer After passing through the PrimaryCaps layer, the tensor data is input into the DigitCaps layer to output a final output.