Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant Representations

Published: 15 October 2018 Publication History


With the growing adoption of machine learning, sharing of learned models is becoming popular. However, in addition to the prediction properties the model producer aims to share, there is also a risk that the model consumer can infer other properties of the training data the model producer did not intend to share. In this paper, we focus on the inference of global properties of the training data, such as the environment in which the data was produced, or the fraction of the data that comes from a certain class, as applied to white-box Fully Connected Neural Networks (FCNNs). Because of their complexity and inscrutability, FCNNs have a particularly high risk of leaking unexpected information about their training sets; at the same time, this complexity makes extracting this information challenging. We develop techniques that reduce this complexity by noting that FCNNs are invariant under permutation of nodes in each layer. We develop our techniques using representations that capture this invariance and simplify the information extraction task. We evaluate our techniques on several synthetic and standard benchmark datasets and show that they are very effective at inferring various data properties. We also perform two case studies to demonstrate the impact of our attack. In the first case study we show that a classifier that recognizes smiling faces also leaks information about the relative attractiveness of the individuals in its training set. In the second case study we show that a classifier that recognizes Bitcoin mining from performance counters also leaks information about whether the classifier was trained on logs from machines that were patched for the Meltdown and Spectre attacks.

  • (2024)Security for Machine Learning-based Software Systems: A Survey of Threats, Practices, and ChallengesACM Computing Surveys10.1145/363853156:6(1-38)Online publication date: 23-Feb-2024
  • (2024)Correlation inference attacks against machine learning modelsScience Advances10.1126/sciadv.adj926010:28Online publication date: 12-Jul-2024
  • (2024)A Differentially Privacy Assisted Federated Learning Scheme to Preserve Data Privacy for IoMT ApplicationsIEEE Transactions on Network and Service Management10.1109/TNSM.2024.339396921:4(4686-4700)Online publication date: Aug-2024
Information & Contributors


Published In

cover image ACM Conferences
CCS '18: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
October 2018
2359 pages
Association for Computing Machinery

New York, NY, United States

Published: 15 October 2018

Published: 15 October 2018


Author Tags

  1. neural networks
  2. permutation equivalence
  3. property inference


  • (2024)Security for Machine Learning-based Software Systems: A Survey of Threats, Practices, and ChallengesACM Computing Surveys10.1145/363853156:6(1-38)Online publication date: 23-Feb-2024
  • (2024)Correlation inference attacks against machine learning modelsScience Advances10.1126/sciadv.adj926010:28Online publication date: 12-Jul-2024
  • (2024)A Differentially Privacy Assisted Federated Learning Scheme to Preserve Data Privacy for IoMT ApplicationsIEEE Transactions on Network and Service Management10.1109/TNSM.2024.339396921:4(4686-4700)Online publication date: Aug-2024
  • (2024)An Empirical Evaluation of the Data Leakage in Federated Graph LearningIEEE Transactions on Network Science and Engineering10.1109/TNSE.2023.332635911:2(1605-1618)Online publication date: Mar-2024
  • (2024)Enhanced Security and Privacy via Fragmented Federated LearningIEEE Transactions on Neural Networks and Learning Systems10.1109/TNNLS.2022.321262735:5(6703-6717)Online publication date: May-2024
  • (2024)Shield Against Gradient Leakage Attacks: Adaptive Privacy-Preserving Federated LearningIEEE/ACM Transactions on Networking10.1109/TNET.2023.331787032:2(1407-1422)Online publication date: Apr-2024
  • (2024)Privacy-Preserving Federated Class-Incremental LearningIEEE Transactions on Machine Learning in Communications and Networking10.1109/TMLCN.2023.33440742(150-168)Online publication date: 2024
  • (2024)Learning to Prevent Input Leakages in the Mobile Cloud InferenceIEEE Transactions on Mobile Computing10.1109/TMC.2023.334033823:7(7650-7663)Online publication date: Jul-2024
  • (2024)Roulette: A Semantic Privacy-Preserving Device-Edge Collaborative Inference Framework for Deep Learning Classification TasksIEEE Transactions on Mobile Computing10.1109/TMC.2023.331230423:5(5494-5510)Online publication date: May-2024
  • (2024)On Data Distribution Leakage in Cross-Silo Federated LearningIEEE Transactions on Knowledge and Data Engineering10.1109/TKDE.2023.3349323(1-17)Online publication date: 2024
  • Show More Cited By

