NOSnoop: an Effective Collaborative Meta-Learning Scheme against Property Inference Attack. Ma, X., Li, B., Jiang, Q., Chen, Y., Gao, S., & Ma, J. IEEE Internet of Things Journal, 2021.  doi  abstract   bibtex   3 downloads  Collaborative learning has been used to train a joint model on geographically diverse data through periodically sharing knowledge. Although participants keep the data locally in collaborative learning, the adversary can still launch inference attacks through participants’ shared information. In this paper, we focus on the property inference attack during model training and design a novel defense mechanism, namely NOSnoop, to defend such an attack. We propose a collaborative meta-learning architecture to learn the common knowledge over all participants and utilize the natural advantage of meta-learning to hide the sensitive property data. We consider both irrelevant property and relevant property preservation in NOSnoop. For irrelevant property preservation, we utilize the inherent advantage of meta-learning to hide the sensitive property data in meta-training support dataset. Thus, the adversary cannot capture the key information related to the sensitive properties and cannot infer victim’s private property successfully. For relevant property preservation, an adversarial game is further proposed to reduce the inference success rate of the adversary. We conduct comprehensive experiments to evaluate the effectiveness of NOSnoop. When hiding the sensitive property data in meta-training support dataset, NOSnoop achieves an inference AUC score as low as 0.4984 for irrelevant property preservation, meaning the adversary cannot distinguish whether the training batch has the sensitive property data or not. When preserving the relevant property, NOSnoop is able to achieve an inference AUC score of 0.5091 without compromising model utility.
@article{ma_nosnoop_2021,
	title = {{NOSnoop}: an {Effective} {Collaborative} {Meta}-{Learning} {Scheme} against {Property} {Inference} {Attack}},
	issn = {2327-4662},
	shorttitle = {{NOSnoop}},
	doi = {10.1109/JIOT.2021.3112737},
	abstract = {Collaborative learning has been used to train a joint model on geographically diverse data through periodically sharing knowledge. Although participants keep the data locally in collaborative learning, the adversary can still launch inference attacks through participants’ shared information. In this paper, we focus on the property inference attack during model training and design a novel defense mechanism, namely NOSnoop, to defend such an attack. We propose a collaborative meta-learning architecture to learn the common knowledge over all participants and utilize the natural advantage of meta-learning to hide the sensitive property data. We consider both irrelevant property and relevant property preservation in NOSnoop. For irrelevant property preservation, we utilize the inherent advantage of meta-learning to hide the sensitive property data in meta-training support dataset. Thus, the adversary cannot capture the key information related to the sensitive properties and cannot infer victim’s private property successfully. For relevant property preservation, an adversarial game is further proposed to reduce the inference success rate of the adversary. We conduct comprehensive experiments to evaluate the effectiveness of NOSnoop. When hiding the sensitive property data in meta-training support dataset, NOSnoop achieves an inference AUC score as low as 0.4984 for irrelevant property preservation, meaning the adversary cannot distinguish whether the training batch has the sensitive property data or not. When preserving the relevant property, NOSnoop is able to achieve an inference AUC score of 0.5091 without compromising model utility.},
	journal = {IEEE Internet of Things Journal},
	author = {Ma, Xindi and Li, Baopu and Jiang, Qi and Chen, Yimin and Gao, Sheng and Ma, Jianfeng},
	year = {2021},
	keywords = {Collaborative work, Computational modeling, Data models, Data privacy, Inference Attack, Internet of Things, Machine Learning, Meta Learning., Privacy, Privacy Preservation, Training},
	pages = {1--1},
} 
Downloads: 3
{"_id":"EbwYJ9DvzhftWDPKX","bibbaseid":"ma-li-jiang-chen-gao-ma-nosnoopaneffectivecollaborativemetalearningschemeagainstpropertyinferenceattack-2021","author_short":["Ma, X.","Li, B.","Jiang, Q.","Chen, Y.","Gao, S.","Ma, J."],"bibdata":{"bibtype":"article","type":"article","title":"NOSnoop: an Effective Collaborative Meta-Learning Scheme against Property Inference Attack","issn":"2327-4662","shorttitle":"NOSnoop","doi":"10.1109/JIOT.2021.3112737","abstract":"Collaborative learning has been used to train a joint model on geographically diverse data through periodically sharing knowledge. Although participants keep the data locally in collaborative learning, the adversary can still launch inference attacks through participants’ shared information. In this paper, we focus on the property inference attack during model training and design a novel defense mechanism, namely NOSnoop, to defend such an attack. We propose a collaborative meta-learning architecture to learn the common knowledge over all participants and utilize the natural advantage of meta-learning to hide the sensitive property data. We consider both irrelevant property and relevant property preservation in NOSnoop. For irrelevant property preservation, we utilize the inherent advantage of meta-learning to hide the sensitive property data in meta-training support dataset. Thus, the adversary cannot capture the key information related to the sensitive properties and cannot infer victim’s private property successfully. For relevant property preservation, an adversarial game is further proposed to reduce the inference success rate of the adversary. We conduct comprehensive experiments to evaluate the effectiveness of NOSnoop. When hiding the sensitive property data in meta-training support dataset, NOSnoop achieves an inference AUC score as low as 0.4984 for irrelevant property preservation, meaning the adversary cannot distinguish whether the training batch has the sensitive property data or not. When preserving the relevant property, NOSnoop is able to achieve an inference AUC score of 0.5091 without compromising model utility.","journal":"IEEE Internet of Things Journal","author":[{"propositions":[],"lastnames":["Ma"],"firstnames":["Xindi"],"suffixes":[]},{"propositions":[],"lastnames":["Li"],"firstnames":["Baopu"],"suffixes":[]},{"propositions":[],"lastnames":["Jiang"],"firstnames":["Qi"],"suffixes":[]},{"propositions":[],"lastnames":["Chen"],"firstnames":["Yimin"],"suffixes":[]},{"propositions":[],"lastnames":["Gao"],"firstnames":["Sheng"],"suffixes":[]},{"propositions":[],"lastnames":["Ma"],"firstnames":["Jianfeng"],"suffixes":[]}],"year":"2021","keywords":"Collaborative work, Computational modeling, Data models, Data privacy, Inference Attack, Internet of Things, Machine Learning, Meta Learning., Privacy, Privacy Preservation, Training","pages":"1–1","bibtex":"@article{ma_nosnoop_2021,\n\ttitle = {{NOSnoop}: an {Effective} {Collaborative} {Meta}-{Learning} {Scheme} against {Property} {Inference} {Attack}},\n\tissn = {2327-4662},\n\tshorttitle = {{NOSnoop}},\n\tdoi = {10.1109/JIOT.2021.3112737},\n\tabstract = {Collaborative learning has been used to train a joint model on geographically diverse data through periodically sharing knowledge. Although participants keep the data locally in collaborative learning, the adversary can still launch inference attacks through participants’ shared information. In this paper, we focus on the property inference attack during model training and design a novel defense mechanism, namely NOSnoop, to defend such an attack. We propose a collaborative meta-learning architecture to learn the common knowledge over all participants and utilize the natural advantage of meta-learning to hide the sensitive property data. We consider both irrelevant property and relevant property preservation in NOSnoop. For irrelevant property preservation, we utilize the inherent advantage of meta-learning to hide the sensitive property data in meta-training support dataset. Thus, the adversary cannot capture the key information related to the sensitive properties and cannot infer victim’s private property successfully. For relevant property preservation, an adversarial game is further proposed to reduce the inference success rate of the adversary. We conduct comprehensive experiments to evaluate the effectiveness of NOSnoop. When hiding the sensitive property data in meta-training support dataset, NOSnoop achieves an inference AUC score as low as 0.4984 for irrelevant property preservation, meaning the adversary cannot distinguish whether the training batch has the sensitive property data or not. When preserving the relevant property, NOSnoop is able to achieve an inference AUC score of 0.5091 without compromising model utility.},\n\tjournal = {IEEE Internet of Things Journal},\n\tauthor = {Ma, Xindi and Li, Baopu and Jiang, Qi and Chen, Yimin and Gao, Sheng and Ma, Jianfeng},\n\tyear = {2021},\n\tkeywords = {Collaborative work, Computational modeling, Data models, Data privacy, Inference Attack, Internet of Things, Machine Learning, Meta Learning., Privacy, Privacy Preservation, Training},\n\tpages = {1--1},\n}\n\n\n\n","author_short":["Ma, X.","Li, B.","Jiang, Q.","Chen, Y.","Gao, S.","Ma, J."],"key":"ma_nosnoop_2021","id":"ma_nosnoop_2021","bibbaseid":"ma-li-jiang-chen-gao-ma-nosnoopaneffectivecollaborativemetalearningschemeagainstpropertyinferenceattack-2021","role":"author","urls":{},"keyword":["Collaborative work","Computational modeling","Data models","Data privacy","Inference Attack","Internet of Things","Machine Learning","Meta Learning.","Privacy","Privacy Preservation","Training"],"metadata":{"authorlinks":{}},"downloads":3},"bibtype":"article","biburl":"https://bibbase.org/zotero/iche","dataSources":["Rxy8umoNP78qdq56v","8BDe79PKmLEoGEieK","yM68t35RzDgJZajbn"],"keywords":["collaborative work","computational modeling","data models","data privacy","inference attack","internet of things","machine learning","meta learning.","privacy","privacy preservation","training"],"search_terms":["nosnoop","effective","collaborative","meta","learning","scheme","against","property","inference","attack","ma","li","jiang","chen","gao","ma"],"title":"NOSnoop: an Effective Collaborative Meta-Learning Scheme against Property Inference Attack","year":2021,"downloads":3}