2022

Truth Serum: Poisoning Machine Learning Models to Reveal Their Secrets

Tramèr, Florian, Shokri, Reza, Joaquin, Ayrton San et al.

Understand

We introduce a new class of attacks on machine learning models.

  • We show that an adversary who can poison a training dataset can cause models trained on this dataset to leak significant private details of training points belonging to other parties.
  • Our active inference attacks connect two independent lines of work targeting the integrity and privacy of machine learning training data.
  • Our attacks are effective across membership inference, attribute inference, and data extraction.

Reading the bibliography…