Evaluation Program, Evaluation Method, and Information Processing Apparatus

The evaluation program efficiently assesses the resistance of machine learning models to membership inference attacks by leveraging attack results from models with varying pseudo-data amounts, reducing the need for repeated training and attacks, and enhancing the efficiency and accuracy of security evaluations.

JP7694211B2Active Publication Date: 2025-06-18FUJITSU LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2021111967
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-07-06
Publication Date
2025-06-18
Estimated Expiration
2041-07-06

AI Technical Summary

Technical Problem

Existing methods for evaluating resistance to membership inference attacks are inefficient, requiring repeated training and attacks, which consume significant time and resources.

Method used

An evaluation program that obtains attack results for machine learning models with varying amounts of pseudo-data, identifies specific data for targeted attacks, and evaluates resistance based on these results, thereby efficiently assessing the resilience to membership inference attacks.

Benefits of technology

This approach allows for a significant reduction in the number of actual attacks needed, decreases computational load, and enables efficient evaluation of resistance to membership inference attacks, thereby improving the speed and accuracy of security assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007694211000001
    Figure 0007694211000001
  • Figure 0007694211000002
    Figure 0007694211000002
  • Figure 0007694211000003
    Figure 0007694211000003
Patent Text Reader

Abstract

To efficiently evaluate resistance against a membership estimation attack.SOLUTION: An information processing device acquires each machine learning model having different amounts of pseudo data simulating training data and used for training, and each attack result of a membership estimation attack to each machine learning model, measured by using a plurality of pieces of data being an attack object by the membership estimation attack. The information processing device identifies specific data on the basis of each attack result among the plurality of pieces of data. The information processing device executes a membership estimation attack using the specific data to a corresponding specific machine learning model while an amount of pseudo data is an amount of pseudo data used for training of each machine learning model. The information processing device evaluates resistance against the membership estimation attack to the specific machine learning model on the basis of each attack result and an attack result to the specific data.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an evaluation program, an evaluation method, and an information processing apparatus.

Background Art

[0002] The development and utilization of systems using machine learning have been rapidly progressing. The operation of machine learning is divided into two phases: a training phase and an inference phase. The training phase is a phase in which machine learning is generated using training data, and the inference phase is a phase in which an inference result is obtained from input data using a trained machine learning model.

[0003] On the other hand, security problems specific to machine learning have also been found. For example, a membership inference attack for estimating whether certain data has been used in a machine learning model is known. When a membership inference attack is used, for example, training data used in a machine learning model related to a disease is detected, resulting in a privacy violation or the like.

[0004] In recent years, as a countermeasure against membership inference attacks, grid research for estimating the change in the resistance of membership inference attacks depending on the amount of synthetic data is known. For example, grid research prepares training data with variously changed amounts of added synthetic data, generates a plurality of machine learning models using them, actually performs an attack on each machine learning model, and comprehensively measures the attack resistance.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Patent Document 2

Patent Document 3

Patent Document 4

Patent Document 5

Summary of the Invention

Problems to be Solved by the Invention

[0006] However, in the above technology, it is necessary to repeat training and attacks, which takes a lot of time for measurement, and it is difficult to efficiently evaluate the resistance to membership inference attacks.

[0007] For example, in grid search, a machine learning model is generated using training data with the amount of pseudo-data changed, an attack is performed on the machine learning model to evaluate the resistance, and further, another machine learning model is generated using training data with the amount of pseudo-data changed, and an attack is performed on that other machine learning model to evaluate the resistance. Thus, in grid search, the generation of the machine learning model and the evaluation of the resistance are repeated, and the evaluation of the resistance takes time.

[0008] In one aspect, an object is to provide an evaluation program, an evaluation method, and an information processing apparatus that can efficiently evaluate the resistance to membership inference attacks.

Means for Solving the Problems

[0009] In the first aspect, the evaluation program causes a computer to obtain, for each machine learning model, an attack result of the membership inference attack against the machine learning model, where the attack result is measured using the machine learning models, each of which is a pseudo-data simulating training data and has a different amount of the pseudo-data used for training, and a plurality of data that are targets of attack by the membership inference attack. Then, among the plurality of data, the evaluation program identifies specific data based on each attack result, and executes the membership inference attack using the specific data against a specific machine learning model whose amount of the pseudo-data corresponds to the amount of the pseudo-data used for training of each machine learning model. Based on each attack result and the attack result against the specific data, the evaluation program evaluates the resistance of the specific machine learning model against the membership inference attack.

Advantages of the Invention

[0010] According to one embodiment, it is possible to efficiently evaluate the resistance against the membership inference attack.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

MODE FOR CARRYING OUT THE INVENTION

[0012] Hereinafter, examples of the evaluation program, evaluation method, and information processing apparatus disclosed in the present application will be described in detail with reference to the drawings. Note that the present invention is not limited by this example. Also, each example can be appropriately combined within a non - conflicting range.

EXAMPLE

[0013] [Description of Information Processing Apparatus] FIG. 1 is a diagram for explaining an information processing apparatus 10 according to Example 1. The information processing apparatus 10 shown in FIG. 1 is an example of a computer apparatus that generates a machine learning model using certain training data and executes prediction or classification using the generated machine learning model.

[0014] Generally, a third party who is not the legitimate rights holder can estimate whether the data (attack target data) they own has been used for training the machine learning model of the information processing apparatus 10 by performing a membership inference attack using black-box access corresponding to the machine learning model. In contrast, the information processing apparatus 10 can prompt the administrator or the like to respond to the membership inference attack by measuring the resistance to the membership inference attack using the attack target data.

[0015] Here, an example of a membership inference attack will be described. FIG. 2 is a diagram for explaining the membership inference attack. As shown in FIG. 2(a), as a premise, the attacker has a data set B that is somewhat similar to the data set A, which is the training data of the attack target model, and has black-box access to the machine learning model to be attacked. Note that black-box access means that although an input can be made to obtain the output, the internal parameters of the machine learning model cannot be known.

[0016] Under such a premise, as shown in FIG. 2(b), the attacker divides the data set B they have into two: "pseudo-training data for the shadow model" and "test data for the shadow model". The shadow model is a machine learning model trained by the attacker and having the same function as the machine learning model to be attacked. The attacker trains the shadow model using the "pseudo-training data for the shadow model".

[0017] In addition, the attacker uses the shadow model and the above two data to train an attack model that outputs whether the input is training data or not, with the output data of the shadow model as the input. Note that the output data corresponds to a confidence vector or the like in the case of a classification model.

[0018] After that, as shown in FIG. 2(c), the attacker inputs the attack target data into the machine learning model to be attacked and inputs the output into the attack model to obtain an inference result as to whether it is training data or not.

[0019] An attacker identifies data that is likely to have been used in the machine learning model of the information processing apparatus 10 through such a membership inference attack. Therefore, the user of the machine learning model may have the content of the unpublicized data identified through the membership inference attack, increasing the risk of leakage of personal information.

[0020] Regarding such a membership inference attack, techniques such as grid search are used to evaluate the attack resistance, but it takes a lot of time for measurement and it is difficult to efficiently evaluate the resistance to the membership inference attack.

[0021] Therefore, the information processing apparatus 10 according to Example 1 utilizes the characteristic that the resistance to the membership inference attack increases as the amount of the pseudo data increases, and efficiently evaluates the resistance to the membership inference attack.

[0022] Specifically, the information processing apparatus 10 acquires each attack result of the membership inference attack against each machine learning model measured using each machine learning model that is pseudo data simulating the training data and has a different amount of pseudo data used for training, and a plurality of data that are attack targets by the membership inference attack. The information processing apparatus 10 identifies specific data among the plurality of data based on each attack result.

[0023] The information processing apparatus 10 executes a membership inference attack using the specific data against a specific machine learning model in which the amount of the pseudo data corresponds to the amount of the pseudo data used for training of each machine learning model. The information processing apparatus 10 evaluates the resistance (MI resistance) of the membership inference attack against the specific machine learning model based on each attack result and the attack result against the specific data.

[0024] FIG. 3 is a diagram for explaining the evaluation of the resistance of the membership inference attack by the information processing apparatus 10 according to Example 1. As shown in FIG. 3, the information processing apparatus 10 generates a plurality of machine learning models using each training data set with a different amount of pseudo data.

[0025] Then, the information processing apparatus 10 obtains the resistance result of the membership inference attack against the first machine learning model generated using the training data including the pseudo-data that is less than the number of pseudo-data used in the machine learning model to be evaluated. Further, the information processing apparatus 10 obtains the resistance result of the membership inference attack against the second machine learning model generated using the training data including the pseudo-data that is more than the number of pseudo-data used in the target machine learning model.

[0026] Then, the information processing apparatus 10 compares the two known attack results, actually performs the attack only on the data for which the attack result has changed, and directly adopts the known result for the data for which the attack result has not changed.

[0027] Therefore, the information processing apparatus 10 can efficiently evaluate the resistance to the membership inference attack by diverting the known attack results and narrowing down the data for which the attack is performed by utilizing the characteristics of the membership inference attack, so that the resistance to the membership inference attack can be efficiently evaluated.

[0028] [Functional Configuration] FIG. 4 is a functional block diagram showing the functional configuration of the information processing apparatus 10 according to the first embodiment. As shown in FIG. 4, the information processing apparatus 10 includes a communication unit 11, a storage unit 12, and a control unit 20.

[0029] The communication unit 11 is a processing unit that controls communication with other devices, and is realized by, for example, a communication interface or the like. For example, the communication unit 11 executes transmission and reception of various data with the administrator's terminal and transmits evaluation results and the like.

[0030] The storage unit 12 is a processing unit that stores various data and programs executed by the control unit 20, and is realized by, for example, a memory or a hard disk. This storage unit 12 stores a dataset DB13, an attack target data DB14, and a model DB15.

[0031] The dataset DB13 is a database that stores data used for training a machine learning model. Figure 5 is a diagram showing an example of the information stored in the dataset DB13. As shown in Figure 5, the dataset DB13 stores a training data group and a test data group.

[0032] The training data group stores the "training data" and the "label" in association with each other. The "training data" stored here contains data used for machine learning, and the "label" contains so-called correct answer information (teacher label). In the example of Figure 5, it is shown that the actual training data A with label A is registered.

[0033] The test data group stores the "test data" and the "label" in association with each other. The "test data" stored here contains data used for testing during the training of machine learning, and the "label" contains so-called correct answer information (teacher label). In the example of Figure 5, it is shown that the actual test data A with label A is registered.

[0034] When assuming a machine learning model that determines whether an image is a dog or something else, the training data and test data include image data with the label "dog" and image data with the label "cat", etc.

[0035] The target data DB14 is a database that stores data targeted by the membership inference attack. Figure 6 is a diagram showing an example of the information stored in the target data DB14. As shown in Figure 6, the target data DB14 stores "target data" that a third party who is not a legitimate rights holder is assumed to estimate whether it was used in the training data. In the example of Figure 6, it is shown that "Data 1" and "Data 2" are registered as "target data".

[0036] Model DB15 is a database that stores various machine learning models used by information processing device 10. Each machine learning model stored here may be generated by information processing device 10, or a known machine learning model generated by another device, administrator, etc. may be registered.

[0037] FIG. 7 is a diagram showing an example of information stored in model DB15. As shown in FIG. 7, model DB15 stores by associating "model" with "type". In the "model" stored here, a machine learning model is registered, and in the "type", information indicating the use, performance, etc. of the machine learning model is registered.

[0038] In the example of FIG. 7, it is shown that a machine learning model M1 generated using a training data set that does not contain any fake data is registered. It is also shown that a machine learning model M2 generated using a training data set in which 10% of the entire training data set is fake data is registered. It is also shown that an attack model that outputs whether the input data was used in the training data according to the input data is registered.

[0039] Control unit 20 is a processing unit that controls the entire information processing device 10 and is realized by, for example, a processor or the like. This control unit 20 has a preprocessing unit 30 and an evaluation unit 40. Note that the preprocessing unit 30 and the evaluation unit 40 are realized by an electronic circuit mounted on a processor or the like, a process executed by a processor, or the like.

[0040] The preprocessing unit 30 has a training unit 31 and an attack measurement unit 32, and is a processing unit that executes preprocessing before evaluating the resistance to membership inference attacks.

[0041] The training unit 31 is a processing unit that executes the training of each machine learning model to generate each machine learning model. Specifically, the training unit 31 generates a plurality of training data sets with the number of pseudo-data changed for a training data set including a training data group and pseudo-data, generates a plurality of machine learning models using each of the plurality of training data sets, and stores them in the storage unit 12. For example, the training unit 31 generates 10 machine learning models with the number of pseudo-data differing by 10% each. Note that the training unit 31 generates pseudo-data by attaching labels to data obtained from the Internet that is similar to the images in the training data, data obtained by rotating the images in the training data, data obtained by changing the scale and color in the training data, etc. Note that the pseudo-data may be registered by an administrator or the like.

[0042] FIG. 8 is a diagram for explaining the generation of each machine learning model in the preprocessing. As shown in FIG. 8(a), the training unit 31 trains the machine learning model M1 using only the training data group without including pseudo-data as the training data set, and generates the machine learning model M1. That is, the training unit 31 executes the training of the machine learning model M1 so that the error between the output of the machine learning model M1 corresponding to the input of the actual training data included in the training data group and the label of the actual training data becomes small.

[0043] Also, as shown in FIG. 8(b), the training unit 31 trains the machine learning model MN using a training data set including the training data group and pseudo-data that is twice the amount of the training data group, and generates the machine learning model MN. For example, the training unit 31 executes the training of the machine learning model MN so that the error between the output of the machine learning model M1 corresponding to the input of the actual training data or pseudo-data and the label of the actual training data or pseudo-data becomes small.

[0044] Also, as shown in FIG. 8(c), the training unit 31 trains an attack model using a training data group and a test data group, and generates an attack model. For example, the training unit 31 inputs each actual training data in the training data group into the machine learning model M1, and inputs the output result (confidence level) of the machine learning model M1 into the attack model. Then, the training unit 31 executes the training of the attack model so that the output value of the attack model becomes "a value indicating that the input data has been used for training". On the other hand, the training unit 31 inputs each actual test data in the test data group into the machine learning model M1, and inputs the output result (confidence level) of the machine learning model M1 into the attack model. Then, the training unit 31 executes the training of the attack model so that the output value of the attack model becomes "a value indicating that the input data has not been used for training". Note that the training unit 31 can also train the attack model using each trained machine learning model.

[0045] The attack measurement unit 32 is a processing unit that generates the resistance to the membership inference attack using a trained machine learning model. Specifically, the attack measurement unit 32 actually executes a membership inference attack on the trained machine learning model, collects the attack results, and stores them in the storage unit 12 or the like.

[0046] FIG. 9 is a diagram for explaining the generation of attack results in the preprocessing. FIG. 9 shows an example in which a membership inference attack has actually been executed on the machine learning model M1 and the machine learning model MN, which are the above examples.

[0047] As shown in Fig. 9(a), the attack measurement unit 32 inputs each of the data from data 1 to data N stored in the target attack data DB14 into the machine learning model M1, and obtains each output value of the machine learning model M1. Then, the attack measurement unit 32 inputs each output value corresponding to each of the data from data 1 to data N into the attack model, obtains each output value of the attack model, and determines the attack result based on each output value. For example, the attack measurement unit 32 determines that the attack is successful for data where the output value of the attack model is equal to or greater than the threshold, and determines that the attack fails for data where the output value of the attack model is less than the threshold. Also, the attack measurement unit 32 calculates the ratio of attack failures in each data stored in the target attack data DB14 as an index representing attack resistance.

[0048] Similarly, as shown in Fig. 9(b), each of the data from data 1 to data N stored in the target attack data DB14 is input into the machine learning model MN, and each output value of the machine learning model MN is obtained. Then, the attack measurement unit 32 inputs each output value corresponding to each of the data from data 1 to data N into the attack model, obtains each output value of the attack model, and determines the attack result based on each output value. The attack measurement unit 32 calculates the ratio of attack failures in each data stored in the target attack data DB14 as an index representing attack resistance.

[0049] Returning to Fig. 4, the evaluation unit 40 has a specifying unit 41 and a resistance evaluation unit 42, and is a processing unit that evaluates the resistance of a machine learning model to a membership inference attack.

[0050] When measuring the resistance of a certain machine learning model to a membership inference attack, the specifying unit 41 compares the known attack results for a plurality of machine learning models trained using training data sets with different amounts of pseudo data, and is a processing unit that specifies the data for actually performing the attack.

[0051] Specifically, the specifying unit 41 specifies a first machine learning model trained using a number of pseudo-data that is less than the number of pseudo-data used for training a certain machine learning model, and obtains a first attack result of the first machine learning model. Further, the specifying unit 41 specifies a second machine learning model trained using a number of pseudo-data that is more than the number of pseudo-data used for training a certain machine learning model, and obtains a second attack result of the second machine learning model. Then, the specifying unit 41 compares the first attack result and the second attack result, and specifies data with different attack results as attack target data for an actual attack target. After that, the specifying unit 41 outputs the specified attack target data to the resilience evaluation unit 42.

[0052] FIG. 10 is a diagram for explaining the specification of attack target data. As shown in FIG. 10, when the specifying unit 41 evaluates the resilience of a machine learning model MM generated using a training data set that is the same amount (ratio 1) of pseudo-data as the training data group, the number of pseudo-data is 0, and the specifying unit 41 obtains an attack result of a machine learning model M1 generated using a training data set with a pseudo-data amount less than that of the machine learning model MM. Further, the specifying unit 41 obtains an attack result of a machine learning model MN generated using a training data set with a number of pseudo-data that is twice the training data (ratio 2) and a pseudo-data amount more than that of the machine learning model MM.

[0053] Then, the specifying unit 41 compares the attack results of each of "Data 1 to Data N" included in each attack result, and specifies "Data 1" with different attack results. As a result, for the machine learning model MM to be evaluated, the specifying unit 41 specifies "Data 1" among the attack target data "Data 1 to Data N" as the attack target.

[0054] The resilience evaluation unit 42 is a processing unit that actually performs a membership inference attack on the data specified by the specifying unit 41 and evaluates the resilience of the machine learning model. In the above example, when the specifying unit 41 evaluates the resilience of the machine learning model MM, an actual attack is performed on "Data 1".

[0055] FIG. 11 is a diagram for explaining the evaluation of resistance to membership inference attacks. As shown in FIG. 11, the resistance evaluation unit 42 inputs "Data 1" among the target data "Data 1 to Data N" into the machine learning model MM to obtain an output result. Subsequently, the resistance evaluation unit 42 inputs the output result of the machine learning model MM into the attack model, and based on the output result of the attack model, determines that the attack is successful. Then, for the target data 1, the resistance evaluation unit 42 adopts the "attack successful" identified above, and for the other target data, adopts the attack result of the machine learning model M1 to generate the attack result of the machine learning model MM. Thereafter, the resistance evaluation unit 42 calculates the ratio of the failed attacks among the attack results as the resistance of the machine learning model MM.

[0056] As described above, the evaluation unit 40 can efficiently perform the resistance evaluation by narrowing down the attack target using the known attack results. In addition, the evaluation unit 40 can efficiently evaluate the resistance to membership inference attacks for all machine learning models with different amounts of pseudo-data by recursively repeating the above process.

[0057] FIG. 12 is a diagram for explaining an example of recursively repeating the evaluation of resistance to membership inference attacks. As shown in FIG. 12, the evaluation unit 40 actually performs attacks on all target data for each of the machine learning model M1 with the least amount of pseudo-data and the machine learning model MN with the most amount of pseudo-data to generate attack results.

[0058] Next, the evaluation unit 40 identifies an unevaluated machine learning model MM that uses the amount of pseudo-data located between two machine learning models with known attack results. Then, the evaluation unit 40 only performs attacks on the data for which the attack results have changed among the attack results of the machine learning model M1 and the attack results of the machine learning model MN, and uses the results for the data for which the attack results have not changed as the attack results.

[0059] Next, the evaluation unit 40 identifies an unevaluated machine learning model M5, which is a machine learning model using the amount of pseudo data located in the middle between the machine learning model M1 and the machine learning model MM. Then, the evaluation unit 40 performs an attack only on the data for which the attack result has changed among the attack results of the machine learning model M1 and the attack results of the machine learning model MM, and uses the result as the attack result for the data for which the attack result has not changed.

[0060] Similarly, the evaluation unit 40 performs an attack only on the data for which the attack result has changed among the attack results of the machine learning model MN and the attack results of the machine learning model MM for an unevaluated machine learning model M9 using the amount of pseudo data located in the middle between the machine learning model MN and the machine learning model MM, and uses the result as the attack result for the data for which the attack result has not changed.

[0061] In this way, the evaluation unit 40 recursively repeats performing an attack only on the data for which the attack result has changed between the front and rear machine learning models for the machine learning model in the middle of the two machine learning models for which the number (amount) of pseudo data has been estimated for resistance. As a result, the evaluation unit 40 can efficiently evaluate the resistance to the membership inference attack.

[0062] In addition, the evaluation unit 40 can also realize visualization of the index by outputting and displaying the estimation result. FIG. 13 is a diagram for explaining an output example of the resistance evaluation of the membership inference attack. In FIG. 13(a), a table with the horizontal axis being "ratio of pseudo data" and the vertical axis being "accuracy of machine learning model" is shown, and in FIG. 13(b), a table with the horizontal axis being "ratio of pseudo data" and the vertical axis being "resistance" is shown.

[0063] As shown in FIG. 13(a), the higher the amount of pseudo data included in the training data, the more the accuracy of the machine learning model deteriorates. On the other hand, as shown in FIG. 13(b), the higher the amount of pseudo data included in the training data, the higher the resistance to the membership inference attack.

[0064] As a result, as shown in FIG. 13(c), the evaluation unit 40 generates a screen indicating that the machine learning model with a ratio of pseudo data of "1" where the accuracy is equal to or higher than a threshold value (e.g., 0.92) and the resistance is equal to or higher than a threshold value (e.g., 0.45) is optimal, and outputs it to the display unit or the like.

[0065] [Flow of processing] FIG. 14 is a flowchart showing the flow of processing according to the first embodiment. As shown in FIG. 14, when the start of processing is instructed (S101: Yes), the control unit 20 of the information processing apparatus 10 generates training data sets with different ratios of pseudo data for each machine learning model (S102).

[0066] Subsequently, the control unit 20 generates each machine learning model with a different amount of pseudo data using each training data set (S103). Further, the control unit 20 generates an attack model using the training data, the test data, and each machine learning model (S104).

[0067] Then, the control unit 20 measures the attack result of the machine learning model that does not use pseudo data using the attack target data DB14 (S105). Similarly, the control unit 20 measures the attack result of the machine learning model that uses the most pseudo data using the attack target data DB14 (S106).

[0068] Thereafter, the control unit 20 selects one unevaluated machine learning model (S107), and acquires the attack result of the machine learning model that uses less pseudo data than the amount of pseudo data used for the selected machine learning model (S108). Similarly, the control unit 20 acquires the attack result of the machine learning model that uses more pseudo data than the amount of pseudo data used for the selected machine learning model (S109).

[0069] Then, the control unit 20 compares each attack result and identifies the data with different attack results as the attack target. Thereafter, the control unit 20 executes an attack only on the attack target to measure the attack result (S111), and evaluates the resistance of the membership inference attack (S112).

[0070] Here, when the control unit 20 continues the process, such as when there is an unevaluated machine learning model (S113: No), it returns to S107 and executes subsequent processes for the unevaluated machine learning model. On the other hand, when the control unit 20 ends the process, such as when there is no unevaluated machine learning model (S113: Yes), it outputs the evaluation result of the resistance to the membership inference attack (S114).

[0071] [Effect] As described above, the information processing apparatus 10 can predict the measurement results under new conditions from the measured results based on the empirically known relationship between the pseudo data and the resistance to the membership inference attack, that is, the relationship in which the resistance to the membership inference attack increases as the pseudo data increases. Therefore, the information processing apparatus 10 can significantly reduce the number of actual attacks, reduce the amount of calculation, and efficiently evaluate the resistance to the membership inference attack.

[0072] In addition, while repeatedly performing the attack, the information processing apparatus 10 can overwhelmingly reduce the number of attacks compared to the grid search, so that the time required for evaluation can be shortened. [Example]

[0073] Now, although the embodiments of the present invention have been described so far, the present invention may be implemented in various different forms other than the above-described embodiments.

[0074] [Numerical values, etc.] The numerical examples, training data examples, number of training data, number of machine learning models, ratio of pseudo data, etc. used in the above embodiments are merely examples and can be arbitrarily changed. Also, the flow of the processes described in each flowchart can be appropriately changed within a range without contradiction. Further, each model can adopt a model generated by various algorithms such as a neural network.

[0075] In addition, each machine learning model, attack model, attack result of the machine learning model with the minimum amount of dummy data, and attack result of the machine learning model with the maximum amount of dummy data may be pre-generated. Further, training data and the like are not limited to image data, and various data formats such as audio data, video data, time series data, and waveform data can be adopted.

[0076] In the above-described embodiment, an example in which the information processing apparatus 10 compares two known attack results has been described, but the present invention is not limited thereto. For example, the information processing apparatus 10 can also compare three or more known attack results with each other and execute the above-described evaluation for an intermediate of combinations having different attack results.

[0077] [System] Regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above-described documents and drawings, they may be arbitrarily changed unless otherwise specified.

[0078] In addition, the specific forms of distribution and integration of the components of each apparatus are not limited to those shown in the drawings. For example, the preprocessing unit 30 and the evaluation unit 40 may be integrated. That is, all or part of the components may be functionally or physically distributed and integrated in arbitrary units according to various loads, usage situations, and the like. Further, each processing function of each apparatus may be realized in whole or in any part thereof by a CPU and a program analyzed and executed by the CPU, or may be realized as hardware by wired logic.

[0079] [Hardware] FIG. 15 is a diagram for explaining a hardware configuration example. As shown in FIG. 15, the information processing apparatus 10 includes a communication device 10a, an HDD (Hard Disk Drive) 10b, a memory 10c, and a processor 10d. Further, each unit shown in FIG. 15 is mutually connected by a bus or the like.

[0080] The communication device 10a is, for example, a network interface card or the like, and communicates with other devices. The HDD 10b stores programs and databases that operate the functions shown in FIG. 4.

[0081] The processor 10d reads out from the HDD 10b or the like a program that executes the same processes as the respective processing units shown in FIG. 4, and expands it in the memory 10c, thereby operating a process that executes each function described in FIG. 4 and the like. For example, this process executes the same functions as the respective processing units of the information processing apparatus 10. Specifically, the processor 10d reads out from the HDD 10b or the like a program having the same functions as the preprocessing unit 30, the evaluation unit 40, and the like. Then, the processor 10d executes a process that executes the same processes as the preprocessing unit 30, the evaluation unit 40, and the like.

[0082] In this way, the information processing apparatus 10 operates as an information processing apparatus that executes an evaluation method by reading out and executing a program. Further, the information processing apparatus 10 can also realize the same functions as those of the above-described embodiments by reading out the program from a recording medium by a medium reading device and executing the read program. Note that the program in this other embodiment is not limited to being executed by the information processing apparatus 10. For example, the above embodiments may be similarly applied when another computer or server executes the program, or when these cooperate to execute the program.

[0083] This program may be distributed via a network such as the Internet. Further, this program may be recorded on a computer-readable recording medium such as a hard disk, a flexible disk (FD), a CD-ROM, a magneto-optical disk (MO), or a digital versatile disc (DVD), and may be executed by being read out from the recording medium by a computer.

Explanation of Reference Numerals

[0084] 10 Information processing apparatus 11 Communication unit 12 Memory unit 13 Dataset DB 14 Target data DB for attack 15 Model DB 20 Control unit 30 Preprocessing unit 31 Training unit 32 Attack measurement unit 40 Evaluation unit 41 Identification unit 42 Tolerance evaluation unit

Claims

1. causing a computer to: obtain, using a first machine learning model that is pseudo data simulating training data and for which the number of pieces of the pseudo data used in training is less than that of a specific machine learning model that is the evaluation target, a second machine learning model for which the number of pieces of the pseudo data is greater than that of the specific machine learning model, and a plurality of data that are the targets of an attack by a membership inference attack, attack results of the membership inference attack against the first machine learning model and the second machine learning model, identify specific data among the plurality of data based on the respective attack results, execute, against the specific machine learning model, the membership inference attack using the specific data, evaluate the resistance of the membership inference attack against the specific machine learning model based on the respective attack results and the attack result for the specific data, and execute a process; an evaluation program characterized by this.

2. The identifying process identifies, as the specific data, data among the plurality of data for which the attack results are different in the respective attack results. The evaluation program according to claim 1, characterized by this.

3. The evaluating process selects the respective attack results for data other than the specific data, generates, using the selected respective attack results and the attack result for the specific data, an attack result against the specific machine learning model, calculates, as the resistance of the membership inference attack of the specific machine learning model, the ratio at which the attack fails in the attack result against the specific machine learning model. The evaluation program according to claim 2, characterized by this.

4. generating a plurality of machine learning models using a plurality of training data sets with different numbers of the pseudo data, Execute the membership inference attack on the first machine learning model generated using the training data set that does not include the suspected data, and generate a first attack result indicating whether each of the plurality of data can be inferred. Execute the membership inference attack on the second machine learning model generated using the training data set that contains the most suspected data, and generate a second attack result indicating whether each of the plurality of data can be inferred. An evaluation program according to any one of claims 1 to 3, characterized in that the computer is caused to execute the processing.

5. The process of obtaining Obtain the first attack result and the second attack result. The process of specifying compares the first attack result and the second attack result, and specifies the specific data among the plurality of data whose attack results are different. An evaluation program according to claim 4, characterized in that.

6. The process of obtaining Until the evaluation of the resistance of the membership inference attack for each of the plurality of machine learning models is completed, sequentially specify unevaluated machine learning models. From the plurality of machine learning models, specify a machine learning model having a smaller number of the suspected data than the unevaluated machine learning model and a machine learning model having a larger number of the suspected data than the unevaluated machine learning model. Obtain the attack results of the two specified machine learning models. The process of specifying Compare the attack results of the two machine learning models to specify the specific data. The process of executing Execute the membership inference attack using the specific data on the unevaluated machine learning model. The process of evaluating Based on the attack results of the two machine learning models and the attack results for the specific data, evaluate the resistance of the membership inference attack against the unevaluated machine learning model. The evaluation program according to claim 5, characterized in that.

7. The obtaining process, the specifying process, the executing process, and the evaluating process recursively repeat the process until the evaluation of the resistance of the membership inference attack against each of the plurality of machine learning models is completed. The evaluation program according to claim 6, characterized in that.

8. A computer A first machine learning model that is pseudo data simulating training data and the number of the pseudo data used for training is less than that of a specific machine learning model to be evaluated, a second machine learning model that the number of the pseudo data is more than that of the specific machine learning model, and each attack result of the membership inference attack against the first machine learning model and the second machine learning model measured using a plurality of data that are targets of the attack by the membership inference attack are obtained. Among the plurality of data, specific data is specified based on each attack result. The membership inference attack using the specific data is executed against the specific machine learning model. Based on each attack result and the attack result for the specific data, the resistance of the membership inference attack against the specific machine learning model is evaluated. An evaluation method characterized by executing a process.

9. An acquisition unit that obtains each attack result of the membership inference attack against the first machine learning model and the second machine learning model, which are pseudo data simulating training data and the number of the pseudo data used for training is less than that of a specific machine learning model to be evaluated, a second machine learning model that the number of the pseudo data is more than that of the specific machine learning model, and a plurality of data that are targets of the attack by the membership inference attack. Among the plurality of data, a specifying unit that specifies specific data based on each of the attack results; An execution unit that executes the membership inference attack using the specific data against the specific machine learning model; An evaluation unit that evaluates the resistance of the membership inference attack against the specific machine learning model based on each of the attack results and the attack result for the specific data; An information processing apparatus, characterized by comprising the above.

Citation Information

Patent Citations

  • Method for training multi-class classifier

    JP2011210252A

  • Assessment device, assessment method, and assessment program

    JP2020160743A

  • Density estimation network for unsupervised anomaly detection

    US20190124045A1

  • Methods and apparatus for asynchronous and interactive machine learning using attention selection techniques

    US20190188564A1

  • Adversarial training of neural networks using information about activation path differentials

    US20190220605A1