Privacy Backdoors: Enhancing Membership Inference through Poisoning Pre-trained Models
Wen, Yuxin, Marchyok, Leo, Hong, Sanghyun, Geiping, Jonas, Goldstein, Tom, Carlini, Nicholas
–arXiv.org Artificial Intelligence
It is commonplace to produce application-specific models by fine-tuning large pre-trained models using a small bespoke dataset. The widespread availability of foundation model checkpoints on the web poses considerable risks, including the vulnerability to backdoor attacks. In this paper, we unveil a new vulnerability: the privacy backdoor attack. This black-box privacy attack aims to amplify the privacy leakage that arises when fine-tuning a model: when a victim fine-tunes a backdoored model, their training data will be leaked at a significantly higher rate than if they had fine-tuned a typical model. We conduct extensive experiments on various datasets and models, including both vision-language models (CLIP) and large language models, demonstrating the broad applicability and effectiveness of such an attack. Additionally, we carry out multiple ablation studies with different fine-tuning methods and inference strategies to thoroughly analyze this new threat. Our findings highlight a critical privacy concern within the machine learning community and call for a reevaluation of safety protocols in the use of open-source pre-trained models.
arXiv.org Artificial Intelligence
Apr-1-2024
- Country:
- South America > Colombia
- Meta Department > Villavicencio (0.04)
- North America > United States
- Oregon (0.04)
- Maryland (0.04)
- California > Orange County
- Anaheim (0.04)
- Europe
- Ireland > Leinster
- County Dublin > Dublin (0.04)
- Germany > Baden-Württemberg
- Tübingen Region > Tübingen (0.04)
- Ireland > Leinster
- South America > Colombia
- Genre:
- Research Report (0.84)
- Industry:
- Technology: