• Latest
  • Trending
Apple Researchers Propose A Method For Reconstructing Training Data From Diverse Machine Learning Models By Ensemble Inversion

Apple Researchers Propose A Method For Reconstructing Training Data From Diverse Machine Learning Models By Ensemble Inversion

November 27, 2021
Just-In: Ethereum Merge Most Likely In August, Says Vitalik Buterin

Just-In: Ethereum Merge Most Likely In August, Says Vitalik Buterin

May 20, 2022
Trader Predicts Crypto Market Will Mimic 2018 Bear Season – Here’s How High Bitcoin Could Go Before Nuking Lower

Trader Predicts Crypto Market Will Mimic 2018 Bear Season – Here’s How High Bitcoin Could Go Before Nuking Lower

May 20, 2022
Terraform Labs, Luna Foundation Guard Bought 3.06m AVAX in total: Avalanche Foundation

Terraform Labs, Luna Foundation Guard Bought 3.06m AVAX in total: Avalanche Foundation

May 20, 2022

TD SYNNEX expands solution offering with Google Cloud

May 20, 2022

Creating an ML Web App and Deploying it on AWS

May 20, 2022
Will Fan Tokens Replace Memecoins Like Shiba Inu and Dogecoin?

Will Fan Tokens Replace Memecoins Like Shiba Inu and Dogecoin?

May 20, 2022
Goldman Sachs: Crypto Drawdown Will Have Little Impact on U.S. Economy

Goldman Sachs: Crypto Drawdown Will Have Little Impact on U.S. Economy

May 20, 2022
Crypto Bear Market: Pantera Partner Sees These Buying Opportunities

Crypto Bear Market: Pantera Partner Sees These Buying Opportunities

May 20, 2022
Australias Commonwealth Bank Halts Crypto Rollout

Australias Commonwealth Bank Halts Crypto Rollout

May 20, 2022
Commonwealth Bank puts crypto trading trial on ice as regulators dither

Commonwealth Bank puts crypto trading trial on ice as regulators dither

May 20, 2022
Ethereum devs tip The Merge will occur in August ‘if everything goes to plan’

Ethereum devs tip The Merge will occur in August ‘if everything goes to plan’

May 20, 2022
Beware, Bitcoin Jumping Back Above $30,000 Could Be A Dead Cat Bounce, Here’s why

Beware, Bitcoin Jumping Back Above $30,000 Could Be A Dead Cat Bounce, Here’s why

May 20, 2022
Deep Tech Central
Sunday, May 29, 2022
Subscription
Sign Up
  • News
    • Artificial Intelligence
    • Crypto
    • CyberSecurity
    • IoT
    • Robotics
    • Quantum Computing
    • Sustainability
    • Telecom
  • Videos
  • DTC – UNV
No Result
View All Result
Deeptech Central
No Result
View All Result

Apple Researchers Propose A Method For Reconstructing Training Data From Diverse Machine Learning Models By Ensemble Inversion

by
November 27, 2021
in Artificial Intelligence
0

Model inversion (MI), where an adversary abuses access to a trained Machine Learning (ML) model in order to infer sensitive information about the model’s original training data, has gotten a lot of attention in recent years. The trained model under assault is frequently frozen during MI and used to direct the training of a generator, such as a Generative Adversarial Network, to rebuild the distribution of the model’s original training data. 

As a result, scrutiny of the capabilities of MI techniques is essential for the creation of appropriate protection techniques. Reconstruction of training data with high quality using a single model is complex. However, existing MI literature does not consider targeting many models simultaneously, which could offer the adversary extra information and viewpoints. If successful, this could result in the disclosure of original training samples, putting the privacy of dataset subjects in jeopardy if the training data contains Personally Identifiable Information.

YOU MAY ALSO LIKE

Creating an ML Web App and Deploying it on AWS

Now You Don’t Need To Present Your Credit Card At Checkout If You Bind Your Facial Images/ Hand Features To Your MasterCard Credit Card

Apple researchers have presented an ensemble inversion technique that uses a generator restricted by a set of trained models with shared subjects or entities to estimate the distribution of original training data. When compared to MI of a single ML model, this technique results in considerable improvements in the quality of the generated samples with distinguishing properties of the dataset entities. Without any dataset, high-quality results were obtained, demonstrating how using an auxiliary dataset similar to the expected training data improves the outcomes. The impact of model diversity in the ensemble is examined in-depth, and extra constraints are used to encourage sharp predictions and high activations for the rebuilt samples, resulting in more accurate training picture reconstruction.

When compared to attacking a single model, the model shows a significant improvement in reconstruction performance. The effects of model diversity on ensemble inversion performance were investigated, and the farthest model sampling (FMS) method was employed to optimize model diversity in a collected ensemble. The model creates an inversion ensemble and determines a class correspondence between various models. The model output vector’s enhanced information was used to generate better restrictions for distinguishing qualities of the target identities.

Using stochastic training techniques like SGD with mini-batches, mainstream DCNNs can be trained on arbitrarily large training data sets. As a result, DCNN models are sensitive to the training dataset’s initial random weights and statistical noise. Because of the stochastic nature of learning algorithms, different versions of models are created, each of which focuses on distinct features despite being trained on the same dataset. As a result, to reduce variance, researchers typically use ensemble learning, which is a simple technique to improve the results of discriminatively trained DCNNs.

Source: https://arxiv.org/pdf/2111.03702.pdf

Ensemble learning is a source of inspiration for this study; however, the concept of the ensemble is distinct. In order to do a model inversion, attackers cannot presume that the models under attack have always been trained using ensemble learning. They may, however, be able to collect connected models in order to build an attack ensemble. In other words, the ensemble in the context of the ensemble inversion attack refers to a collection of correlated models that attackers can gather from a variety of sources without requiring that the collected models have been trained using ensemble learning. Researchers or organizations, for example, will continue to get new training data and train and disseminate updates to current models, which may be gathered and utilized as an ensemble by an attacker.

When the proposed strategies are used, the MNIST digit reconstruction accuracy improves by 70.9 percent for the data-free experiment and 17.9 percent for the auxiliary data-based trial. Over the baseline experiment, the accuracy of face reconstruction has been enhanced by 21.1 percent. The goal of this study is to conduct a systemic examination of the presented strategies’ possible impact on model inversion. The development of corresponding protection mechanisms against such ensemble inversion attacks will be the focus of future versions.

Conclusion

The ensemble inversion technique is proposed in the study, which takes advantage of the variety of an ensemble of ML models to improve model inversion performance. In addition, one-hot loss and maximum output activation loss are incorporated, resulting in an even higher level of sample quality. Meanwhile, filtering out generated samples with low maximum activations of the attacked models can help the reconstructions stand out even more. Furthermore, frequent scenarios for getting target model variance are explored and thoroughly investigated in order to determine how to target model diversity affects ensemble inversion performance.

Paper: https://arxiv.org/pdf/2111.03702.pdf

The post Apple Researchers Propose A Method For Reconstructing Training Data From Diverse Machine Learning Models By Ensemble Inversion appeared first on MarkTechPost.

Share196Tweet123Share49

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Search

No Result
View All Result

Recent News

  • Just-In: Ethereum Merge Most Likely In August, Says Vitalik Buterin
  • Trader Predicts Crypto Market Will Mimic 2018 Bear Season – Here’s How High Bitcoin Could Go Before Nuking Lower
  • Terraform Labs, Luna Foundation Guard Bought 3.06m AVAX in total: Avalanche Foundation
  • About
  • Privacy Policy
  • Sign Up
  • Contact Us
  • About
  • Contact
  • Deeptech Central
  • Elementor #10628
  • Newsletter
  • Privacy Policy
  • Sign Up

© 2018-2021 DeepTech Central. - by MintMore Inc..

No Result
View All Result
  • News
    • Artificial Intelligence
    • Crypto
    • CyberSecurity
    • IoT
    • Robotics
    • Quantum Computing
    • Sustainability
    • Telecom
  • Videos
  • DTC – UNV

© 2018-2021 DeepTech Central. - by MintMore Inc..

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Stay Updated. Subscribe Today.

Join the community of 10K+ scholars & entrepreneurs.