White-box vs Black-box: Bayes Optimal Strategies for Membership Inference
Alexandre Sablayrolles · Douze Matthijs · Cordelia Schmid · Yann Ollivier · Herve Jegou

Tue Jun 11th 04:25 -- 04:30 PM @ Room 102

Membership inference determines, given a sample and trained parameters of a machine learning model, whether the sample was part of the training set. In this paper, we derive the optimal strategy for membership inference with a few assumptions on the distribution of the parameters. We show that optimal attacks only depend on the loss function, and thus black-box attacks are as good as white-box attacks. As the optimal strategy is not tractable, we provide approximations of it leading to several inference methods, and show that existing membership inference methods are other approximations as well. Our membership attacks outperform the state of the art in various settings, ranging from a simple logistic regression to more complex architectures and datasets, such as ResNet-101 and Imagenet.

Author Information

Alexandre Sablayrolles (Facebook AI Research)
Douze Matthijs (Facebook AI Research)
Cordelia Schmid (Inria/Google)
Yann Ollivier (Facebook Artificial Intelligence Research)
Herve Jegou (Facebook AI Research)

Related Events (a corresponding poster, oral, or spotlight)

More from the Same Authors