跳到主要导航 跳到搜索 跳到主要内容

Oriole: Thwarting Privacy Against Trustworthy Deep Learning Models

  • Liuqiao Chen
  • , Hu Wang
  • , Benjamin Zi Hao Zhao
  • , Minhui Xue
  • , Haifeng Qian*
  • *此作品的通讯作者
  • East China Normal University
  • University of Adelaide
  • University of New South Wales

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Deep Neural Networks have achieved unprecedented success in the field of face recognition such that any individual can crawl the data of others from the Internet without their explicit permission for the purpose of training high-precision face recognition models, creating a serious violation of privacy. Recently, a well-known system named Fawkes [37] (published in USENIX Security 2020) claimed this privacy threat can be neutralized by uploading cloaked user images instead of their original images. In this paper, we present Oriole, a system that combines the advantages of data poisoning attacks and evasion attacks, to thwart the protection offered by Fawkes, by training the attacker face recognition model with multi-cloaked images generated by Oriole. Consequently, the face recognition accuracy of the attack model is maintained and the weaknesses of Fawkes are revealed. Experimental results show that our proposed Oriole system is able to effectively interfere with the performance of the Fawkes system to achieve promising attacking results. Our ablation study highlights multiple principal factors that affect the performance of the Oriole system, including the DSSIM perturbation budget, the ratio of leaked clean user images, and the numbers of multi-cloaks for each uncloaked image. We also identify and discuss at length the vulnerabilities of Fawkes. We hope that the new methodology presented in this paper will inform the security community of a need to design more robust privacy-preserving deep learning models.

源语言英语
主期刊名Information Security and Privacy - 26th Australasian Conference, ACISP 2021, Proceedings
编辑Joonsang Baek, Sushmita Ruj
出版商Springer Science and Business Media Deutschland GmbH
550-568
页数19
ISBN(印刷版)9783030905668
DOI
出版状态已出版 - 2021
活动26th Australasian Conference on Information Security and Privacy, ACISP 2021 - Virtual, Online
期限: 1 12月 20213 12月 2021

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
13083 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议26th Australasian Conference on Information Security and Privacy, ACISP 2021
Virtual, Online
时期1/12/213/12/21

指纹

探究 'Oriole: Thwarting Privacy Against Trustworthy Deep Learning Models' 的科研主题。它们共同构成独一无二的指纹。

引用此