Updates-Leak: Data Set Inference and Reconstruction Attacks in Online Learning

Ahmed Salem, Apratim Bhattacharya, Michael Backes, Mario Fritz, Yang Zhang

Introduction

Machine learning (ML) has progressed rapidly during the past decade. A key factor that drives the current ML development is the unprecedented large-scale data. In consequence, collecting high-quality data becomes essential for building advanced ML models. Data collection is a continuous process, which in turn transforms the ML model training into a continuous process as well: Instead of training an ML model for once and keeping on using it afterwards, the model’s owner needs to keep on updating the model with newly-collected data. As training from scratch is often prohibitive, this is often achieved by online learning. We refer to the dataset used to perform model update as the updating set.

In this paper, our main research question is: Can different outputs of an ML model’s two versions queried with the same set of data samples leak information of the corresponding updating set?. This constitutes a new attack surface against machine learning models. Information leakage of the updating set may compromise the intellectual property and data privacy of the model owner.

We concentrate on the most common ML application – classification. More importantly, we target black-box ML models – the most difficult attack setting where an adversary does not have access to her target model’s parameters but can only query the model with her data samples and obtain the corresponding prediction results, i.e., posteriors in the case of classification. Moreover, we assume the adversary has a local dataset from the same distribution as the target model’s training set, and the ability to establish the same model as the target model with respect to model architecture. Finally, we only consider updating sets which contain up to 100 newly collected data samples. Note that this is a simplified setting and a step towards real-world setting.

In total, we propose four different attacks in this surface which can be categorized into two classes, namely, single-sample attack class and multi-sample attack class. The two attacks in the single-sample attack class concentrate on a simplified case when the target ML model is updated with one single data sample. We investigate this case to show whether an ML model’s two versions’ different outputs indeed constitute a valid attack surface. The two attacks in the multi-sample attack class tackle a more general and complex case when the updating set contains multiple data samples.

Among our four attacks, two (one for each attack class) aim at reconstructing the updating set which are the first attempts in this direction. Compared to many previous attacks inferring certain properties of a target model’s training set , a dataset reconstruction attack leads to more severe consequences.

Our experiments show that indeed, the output difference of the same ML model’s two different versions can be exploited to infer information about the updating set. We detail our contributions as the following.

General Attack Construction. Our four attacks follow a general structure, which can be formulated into an encoder-decoder style. The encoder realized by a multilayer perceptron (MLP) takes the difference of the target ML model’s outputs, namely posterior difference, as its input while the decoder produces different types of information about the updating set with respect to different attacks.

To obtain the posterior difference, we randomly select a fixed set of data samples, namely probing set, and probe the target model’s two different versions (the second-version model is obtained by updating the first-version model with an updating set). Then, we calculate the difference between the two sets of posteriors as the input for our attack’s encoder.

Single-Sample Attack Class. The single-sample attack class contains two attacks: Single-sample label inference attack and single-sample reconstruction attack. The first attack predicts the label of the single sample used to update the target model. We realize the corresponding decoder for the attack by a two-layer MLP. Our evaluation shows that our attack is able to achieve a strong performance, e.g., 0.96 accuracy on the CIFAR-10 dataset .

The single-sample reconstruction attack aims at reconstructing the updating sample. We rely on autoencoder (AE). In detail, we first train an AE on a different set of data samples. Then, we transfer the AE’s decoder into our attack model as its sample reconstructor. Experimental results show that we can reconstruct the single sample with a performance gain (with respect to mean squared error) of 22% for the MNIST dataset , 107.1% for the CIFAR-10 dataset, and 114.7% for the Insta-NY dataset , over randomly picking a sample affiliated with the same label of the updating sample.

Multi-Sample Attack Class. The multi-sample attack class includes multi-sample label distribution estimation attack and multi-sample reconstruction attack. Multi-sample label distribution estimation attack estimates the label distribution of the updating set’s data samples. It is a generalization of the label inference attack in the single-sample attack class. We realize this attack by setting up the attack model’s decoder as a multilayer perceptron with a fully connected layer and a softmax layer. Kullback-Leibler divergence (KL-divergence) is adopted as the model’s loss function. Our experiments demonstrate the effectiveness of this attack. For the CIFAR-10 dataset, when the updating set’s cardinality is 100, our attack model achieves a 0.00384 KL-divergence which outperforms random guessing by a factor of 2.5. Moreover, the accuracy of predicting the most frequent label is 0.29 which is almost 3 times higher than random guessing.

Our last attack, namely multi-sample reconstruction attack, aims at generating all samples in the updating set. This is a much more complex attack than the previous ones. The decoder for this attack is assembled with two components. The first one learns the data distribution of the updating set samples. In order to achieve coverage and accuracy of the reconstructed samples, we propose a novel hybrid generative model, namely CBM-GAN. Different from the standard generative adversarial networks (GANs), our Conditional Best of Many GAN (CBM-GAN) introduces a “Best Match” loss which ensures that each sample in the updating set is reconstructed accurately. The second component of our decoder relies on machine learning clustering to group the generated data samples by CBM-GAN into clusters and take the central sample of each cluster as one final reconstructed sample. Our evaluation shows that our approach outperforms all baselines when reconstructing the updating set on all MNIST, CIFAR-10, and Insta-NY datasets.

Preliminaries

In this section, we start by introducing online learning, then present our threat model, and finally introduce the datasets used in our experiments.

In this paper, we focus on the most common ML task – classification. An ML classifier M\mathcal{M} is essentially a function that maps a data sample x∈Xx\in\mathcal{X} to posterior probabilities y∈Yy\in\mathcal{Y}, i.e., M:X→Y\mathcal{M}:\mathcal{X}\rightarrow\mathcal{Y}. Here, y∈Yy\in\mathcal{Y} is a vector with each entry indicating the probability of xx being classified to a certain class or affiliated with a certain label. The sum of all values in yy is 1. To train an ML model, we need a set of data samples, i.e., training set. The training process is performed by a certain optimization algorithm, such as ADAM, following a predefined loss function.

A trained ML model M\mathcal{M} can be updated with an updating set denoted by Dupdate\mathcal{D}_{\it update}. The model update is performed by further training the model with the updating set using the same optimization algorithm on the basis of the current model’s parameters. More formally, given an updating set Dupdate\mathcal{D}_{\it update} and a trained ML model M\mathcal{M}, the updating process Fupdate\mathcal{F}_{\it update} can be defined as Fupdate:Dupdate,M→M′\mathcal{F}_{\it update}:\mathcal{D}_{\it update},\mathcal{M}\rightarrow\mathcal{M^{\prime}} where M′\mathcal{M^{\prime}} is the updated version of M\mathcal{M}.

2 Threat Model

For all of our four attacks, we consider an adversary with black-box access to the target model. This means that the adversary can only query the model with a set of data samples, i.e., her probing set, and obtain the corresponding posteriors. This is the most difficult attack setting for the adversary . We also assume that the adversary has a local dataset which comes from the same distribution as the target model’s training set following previous works . Moreover, we consider the adversary to be able to establish the same ML model as the target ML model with respect to model architecture. This can be achieved by performing model hyperparameter stealing attacks . The adversary needs these two information to establish a shadow model which mimics the behavior of the target model to derive data for training her attack model (see Section 3). Also, part of the adversary’s local dataset will be used as her probing set. Finally, we assume that the target ML model is updated only with new data, i.e., the updating set and the training set are disjoint.

We later show in Section 6 that the two assumptions, i.e., the adversary’s knowledge of the target model’s architecture and her possession of a dataset from the same distribution as the target model’s training set, can be further relaxed.

3 Datasets Description

For our experimental evaluation, we use three datasets: MNIST, CIFAR-10, and Insta-NY. Both MNIST and CIFAR-10 are benchmark datasets for various ML security and privacy tasks. MNIST is a 10-class image dataset, it consists of 70,000 28×\times28 grey-scale images. Each image contains in its center a handwritten digit. Images in MNIST are equally distributed over 10 classes. CIFAR-10 contains 60,000 32×\times32 color images. Similar to MNIST, CIFAR-10 is also a 10-class balanced dataset. Insta-NY contains a sample of Instagram users’ location check-in data in New York. Each check-in represents a user visiting a certain location at a certain time. Each location is affiliated with a category. In total, there are eight different categories. Our ML task for Insta-NY is to predict each location’s category. We use the number of check-ins happened at each location in each hour on a weekly base as the location’s feature vector. We further filter out locations with less than 50 check-ins, in total, we have 19,215 locations for the dataset. In Section 6, we further use Insta-LA which contains the check-in data from Los Angeles for our threat model relaxation experiments.

General Attack Pipeline

Our general attack pipeline contains three phases. In the first phase, the adversary generates her attack input, i.e., posterior difference. In the second phase, our encoder transforms the posterior difference into a latent vector. In the last phase, the decoder decodes the latent vector to produce different information of the updating set with respect to different attacks. Figure 1 provides a schematic view of our attack pipeline.

In this section, we provide a general introduction for each phase of our attack pipeline. In the end, we present our strategy of deriving data to train our attack models.

Recall that we aim at investigating the information leaked from posterior difference of a model’s two versions when queried with the same set of data samples. To create this posterior difference, the adversary first needs to pick a set of data samples as her probing set, denoted by Dprobe\mathcal{D}_{\it probe}. In this work, the adversary picks a random sample of data samples (from her local dataset) to form Dprobe\mathcal{D}_{\it probe}. Choosing or crafting a specific set of data samples as the probing set may further improve attack efficiency, we leave this as a future work. Next, the adversary queries the target ML model M\mathcal{M} with all samples in Dprobe\mathcal{D}_{\it probe} and concatenates the received outputs to form a vector yprobey_{\it probe}. Then, she probes the updated model M′\mathcal{M^{\prime}} with samples in Dprobe\mathcal{D}_{\it probe} and creates a vector yprobe′y^{\prime}_{\it probe} accordingly. In the end, she sets the posterior difference, denoted by δ\delta, to the difference of both outputs:

Note that the dimension of δ\delta is the product of Dprobe\mathcal{D}_{\it probe}’s cardinality and the number of classes of the target dataset. For this paper, both CIFAR-10 and MNIST are 10-class datasets, while Insta-NY is an 8-class dataset. As our probing set always contains 100 data samples, this indicates the dimension of δ\delta is 1,000 for CIFAR-10 and MNIST, and 800 for Insta-NY.

2 Encoder Design

All our attacks share the same encoder structure, we model it with a multilayer perceptron. The number of layers inside the encoder depends on the dimension of δ\delta: Longer δ\delta requires more layers in the encoder. As our δ\delta is a 1,000-dimension vector for the MNIST and CIFAR-10 datasets, and 800-dimension vector for the Insta-NY dataset, we use two fully connected layers in the encoder. The first layer transforms δ\delta to a 128-dimension vector and the second layer further reduces the dimension to 64. The concrete architecture of our encoder is presented in Appendix B.

3 Decoder Structure

Our four attacks aim at inferring different information of Dupdate\mathcal{D}_{\it update}, ranging from sample labels to the updating set itself. Thus, we construct different decoders for different attacks with different techniques. The details of these decoders will be presented in the following sections.

4 Shadow Model

Our encoder and decoder need to be trained jointly in a supervised manner. This indicates that we need ground truth data for model training. Due to our minimal assumptions, the adversary cannot get the ground truth from the target model. To solve this problem, we rely on shadow models following previous works . A shadow model is designed to mimic the target model. By controlling the training process of the shadow model, the adversary can derive the ground truth data needed to train her attack models.

As presented in Section 2, our adversary knows (1) the architecture of the target model and (2) a dataset coming from the same distribution as the target dataset. To build a shadow model Mshadow\mathcal{M}_{\it shadow}, the adversary first establishes an ML model with the same structure as the target model. Then, she gets a shadow dataset Dshadow\mathcal{D}_{\it shadow} from her local dataset (the rest is used as Dprobe\mathcal{D}_{\it probe}) and splits it into two parts: Shadow training set Dshadowtrain\mathcal{D}_{\it shadow}^{\it train} and shadow updating set Dshadowupdate\mathcal{D}_{\it shadow}^{\it update}. Dshadowtrain\mathcal{D}_{\it shadow}^{\it train} is used to train the shadow model while Dshadowupdate\mathcal{D}_{\it shadow}^{\it update} is further split to mm datasets: Dshadowupdate1⋯Dshadowupdatem\mathcal{D}_{\it shadow}^{\it update^{1}}\cdots\mathcal{D}_{\it shadow}^{\it update^{m}}. The number of samples in each of the mm datasets depends on the attack. For instance, our single-sample class attacks require each dataset containing a single sample. The adversary then generates mm shadow updated models M′shadow1⋯M′shadowm\mathcal{M^{\prime}}_{\it shadow}^{1}\cdots\mathcal{M^{\prime}}_{\it shadow}^{m} by updating the shadow model Mshadow\mathcal{M}_{\it shadow} with mm shadow updating sets in parallel.

The adversary, in the end, probes the shadow and updated shadow models with her probing set Dprobe\mathcal{D}_{\it probe}, and calculates the shadow posterior difference δshadow1⋯δshadowm\delta_{\it shadow}^{1}\cdots\delta_{\it shadow}^{m}. Together with the corresponding shadow updating set’s ground truth information (depending on the attack), the training data for her attack model is derived.

More generally, the training set for each of our attack models contains mm samples corresponding to Dshadowupdate1⋯Dshadowupdatem\mathcal{D}_{\it shadow}^{\it update^{1}}\cdots\mathcal{D}_{\it shadow}^{\it update^{m}}. In all our experiments, we set mm to 10,000. In addition, we create 1,000 updated models for the target model, this means the testing set for each attack model contains 1,000 samples, corresponding to Dtargetupdate1⋯Dtargetupdate1,000\mathcal{D}_{\it target}^{\it update^{1}}\cdots\mathcal{D}_{\it target}^{\it update^{1,000}}.

Single-sample Attacks

In this section, we concentrate on the case when an ML model is updated with a single sample. This is a simplified attack scenario and we aim to examine the possibility of using posterior difference to infer information about the updating set. We start by introducing the single-sample label inference attack, then, present the single-sample reconstruction attack.

Attack Definition. Our single-sample label inference attack takes the posterior difference as the input and outputs the label of the single updating sample. More formally, given a posterior difference δ\delta, our single-sample label inference attack is defined as follows:

Methodology. To recap, the general construction of the attack model consists of an MLP-based encoder which takes the posterior difference as its input and outputs a latent vector μ\mu. For this attack, the adversary constructs her decoder also with an MLP which is assembled with a fully connected layer and a softmax layer to transform the latent vector to the corresponding updating sample’s label. The concrete architecture of our ALI\mathcal{A}_{\it LI}’s decoder is presented in Appendix C.

To obtain the data for training ALI\mathcal{A}_{\it LI}, the adversary generates ground truth data by creating a shadow model as introduced in Section 3 while setting the shadow updating set’s cardinality to 1. Then, the adversary trains her attack model ALI\mathcal{A}_{\it LI} with a cross-entropy loss. Our loss function is,

To perform the label inference attack, the adversary constructs the posterior difference as introduced in Section 3, then feeds it to the attack model ALI\mathcal{A}_{\it LI} to obtain the label.

Experimental Setup. We evaluate the performance of our single-sample label inference attack using the MNIST, CIFAR-10, and Insta-NY datasets. First, we split each dataset into three disjoint datasets: The target dataset Dtarget\mathcal{D}_{\it target}, the shadow dataset Dshadow\mathcal{D}_{\it shadow}, and the probing dataset Dprobe\mathcal{D}_{\it probe}. As mentioned before, Dprobe\mathcal{D}_{\it probe} contains 100 data samples. We then split Dshadow\mathcal{D}_{\it shadow} to Dshadowtrain\mathcal{D}_{\it shadow}^{\it train} and Dshadowupdate\mathcal{D}_{\it shadow}^{\it update} to train the shadow model as well as updating it (see Section 3). The same process is applied to train and update the target model with Dtarget\mathcal{D}_{\it target}. As mentioned in Section 3, we build 10,000 and 1,000 updated models for shadow and target models, respectively. This means the training and testing sets for our attack model contain 10,000 and 1,000 samples, respectively.

We use convolutional neural network (CNN) to build shadow and target models for both CIFAR-10 and MNIST datasets, and a multilayer perceptron (MLP) for the Insta-NY dataset. The CIFAR-10 model consists of two convolutional layers, one max pooling layer, three fully connected layers, and a softmax layer. The MNIST model consists of two convolutional layers, two fully connected layers, and a softmax layer. Finally, the Insta-NY model consists of three fully connected layers and a softmax layer. The concrete architectures of the models are presented in Appendix A.

All shadow and target models’ training sets contain 10,000 images for CIFAR-10 and MNIST, and 5,000 samples for Insta-NY. We train the CIFAR-10, MNIST and Insta-NY models for 50, 25, and 25 epochs, respectively, with a batch size of 64. To create an updated ML model, we perform a single-epoch training. Finally, we adopt accuracy to measure the performance of the attack. All of our experiments are implemented using Pytorch . For reproducibility purposes, our code will be made available.

Results. Figure 2 depicts the experimental results. As we can see, ALI\mathcal{A}_{\it LI} achieves a strong performance with an accuracy of 0.97 on the Insta-NY dataset, 0.96 on the CIFAR-10 dataset, and 0.68 on the MNIST dataset. Moreover, our attack significantly outperforms the baseline model, namely Random, which simply guesses a label over all possible labels. As both CIFAR-10 and MNIST contain 10 balanced classes, the baseline model’s result is approximately 10%. For the Insta-NY dataset, since it is not balanced, we randomly sample a label for each sample to calculate the baseline which results in approximately 29% accuracy. Our evaluation shows that the different outputs of an ML model’s two versions indeed leak information of the corresponding updating set.

2 Single-sample Reconstruction Attack

Attack Definition. Our single-sample reconstruction attack takes one step further to construct the data sample used to update the model. Formally, given a posterior difference δ\delta, our single-sample reconstruction attack, denoted by ASSR\mathcal{A}_{\it SSR}, is defined as follows:

where xupdatex_{\it update} denotes the sample used to update the model (Dupdate={xupdate}\mathcal{D}_{\it update}=\{x_{\it update}\}).

Methodology. Reconstructing a data sample is a much more complex task than predicting the sample’s label. To tackle this problem, we need an ML model which is able to generate a data sample in the complex space. To this end, we rely on autoencoder (AE).

Autoencoder is assembled with an encoder and a decoder. Different from our attacks, AE’s goal is to learn an efficient encoding for a data sample: Its encoder encodes a sample into a latent vector and its decoder tries to decode the latent vector to reconstruct the same sample. This indicates AE’s decoder itself is a data sample reconstructor. For our attack, we first train an AE, then transfer the AE’s decoder to our attack model as the initialization of the attack’s decoder. Figure 3 provides an overview of the attack methodology. The concrete architectures of our AEs’ encoders and decoders are presented in Appendix D.

After the autoencoder is trained, the adversary takes its decoder and appends it to her attack model’s encoder. To establish the link, the adversary adds an additional fully connected layer to its encoder which transforms the dimensions of the latent vector μ\mu to the same dimension as μAE\mu_{\it AE}.

We divide the attack model training process into two phases. In the first phase, the adversary uses her shadow dataset to train an AE with the previously mentioned model architecture. In the second phase, she follows the same procedure for single-sample label inference attack to train her attack model. Note that the decoder from AE here serves as the initialization of the decoder, this means it will be further trained together with the attack model’s encoder. To train both autoencoder and our attack model, we use mean squared error (MSE) as the loss function. Our objective is,

where x^update\hat{x}_{\it update} is our predicted data sample. We again adopt ADAM as the optimizer.

Experimental Setup. We use the same experimental setup as the previous attack (see Section 4.1) except for the evaluation metric. In detail, we adopt MSE to measure our attack’s performance instead of accuracy.

We construct two baseline models, namely Label-random and Random. Both of these baseline models take a random data sample from the adversary’s shadow dataset. The difference is that the Label-random baseline picks a sample within the same class as the target updating sample, while the Random baseline takes a random data sample from the whole shadow dataset of the adversary. The Label-random baseline can be implemented by first performing our single-sample label inference attack to learn the label of the data sample and then picking a random sample affiliated with the same label.

Results. First, our single-sample reconstruction attack achieves a promising performance. As shown in Figure 4, our attack on the MNIST dataset outperforms the Random baseline by 36% and more importantly, outperforms the Label-random baseline by 22%. Similarly, for the CIFAR-10 and Insta-NY datasets, our attack achieves an MSE of 0.014 and 0.68 which is significantly better than the two baseline models, i.e., it outperforms the Label-random (Random) baselines by a factor of 2.1 (2.2) and 2.1 (2.3), respectively. The difference between our attack’s performance gain over the baseline models on the MNIST and on the other datasets is expected as the MNIST dataset is more homogeneous compared to the other two. In other words, the chance of picking a random data sample similar to the updating sample is much higher in the MNIST dataset than in the other datasets.

Secondly, we compare our attack’s performance against the results of the autoencoder for sample reconstruction. Note that AE takes the original data sample as input and outputs the reconstructed one, thus it is considered as an oracle, since the adversary does not have access to the original updating sample. Here, we just use AE’s result to show the best possible result for our attack. From Figure 4, we observe that AE achieves 0.042, 0.0043, and 0.51 MSE for the MNIST, CIFAR-10, and Insta-NY datasets, respectively, which indeed outperforms our attack. However, our attack still has a comparable performance.

Finally, Figure 5 visualizes some randomly sampled reconstructed images by our attack on MNIST. The first row depicts the original images used to update the models and the second row shows the result of our attack. As we can see, our attack is able to reconstruct images that are visually similar to the original sample with respect to rotation and shape. We also show the result of AE in the third row in Figure 5 which as mentioned before, is the upper bound for our attack. The results from Figure 4 and Figure 5 demonstrate the strong performance of our attack.

Multi-sample Attacks

After demonstrating the effectiveness of our attacks against the updating set with a single sample, we now focus on a more general attack scenario where the updating set contains multiple data samples that are never seen during the training. We introduce two attacks in the multi-sample attack class: Multi-sample label distribution estimation attack and multi-sample reconstruction attack.

Attack Definition. Our first attack in the multi-label attack class aims at estimating the label distribution of the updating set’s samples. It can be considered as a generalization of the label inference attack in the single-sample attack class. Formally, the attack is defined as:

where qq as a vector denotes the distribution of labels over all classes for samples in the updating set.

Methodology. The adversary uses the same encoder structure as presented in Section 3 and the same decoder structure of the label inference attack (Section 4.1). Since the label distribution estimation attack estimates a probability vector qq instead of performing classification, we use Kullback-–Leibler divergence (KL-divergence) as our objective function:

To train the attack model ALDE\mathcal{A}_{\it LDE}, the adversary first generates her training data as mentioned in Section 3. She then trains ALDE\mathcal{A}_{\it LDE} with the posterior difference δshadow1⋯δshadowm\delta_{\it shadow}^{1}\cdots\delta_{\it shadow}^{m} as the input and the normalized label distribution of their corresponding updating sets as the output. We assume the adversary knows the cardinality of the updating set. We try to relax this assumption later in our evaluation.

Experimental Setup. We evaluate our label distribution estimation attack using updating set of cardinalities 10 and 100. For the two different cardinalities, we build attack models as mentioned in the methodology. All data samples in each updating set for the shadow and target models are sampled uniformly, thus each sample (in both training and testing set) for the attack model, which corresponds to an updating set, has the same label distribution of the original dataset. We use a batch size of 64 when updating the models.

For evaluation metrics, we calculate KL-divergence for each testing sample (corresponding to an updating set on the target model) and report the average result over all testing samples (1,000 in total). Besides, we also measure the accuracy of predicting the most frequent label over samples in the updating set. We randomly sample a dataset with the same size as the updating set and use its samples’ label distribution as the baseline, namely Random.

Results. We report the result for our label distribution estimation attack in Figure 6. As shown, ALDE\mathcal{A}_{\it LDE} achieves a significantly better performance than the Random baseline on all datasets. For the updating set with 100 data samples on the CIFAR-10 dataset, our attack achieves 3 and 2.5 times better accuracy and KL-divergence, respectively, than the Random baseline. Similarly, for the MNIST and Insta-NY datasets, our attack achieves 1.5 and 4.8 times better accuracy, and 2 and 7.9 times better KL-divergence. Furthermore, ALDE\mathcal{A}_{\it LDE} achieves a similar improvement over the Random baseline for the updating set of size 10.

Recall that the adversary is assumed to know the cardinality of the updating set in order to train her attack model, we further test whether we can relax this assumption. To this end, we first update the shadow model with 100 samples while updating the target model with 10 samples. As shown in 6(a) and 6(c) Transfer 100-10, our attack still has a similar performance as the original attack. However, when the adversary updates her shadow model with 10 data samples while the target model is updated with 100 data samples (6(b) and 6(d) Transfer 10-100), our attack performance drops significantly, in particular for KL-divergence on the CIFAR-10 dataset. We believe this is due to the 10 samples not providing enough information for the attack model to generalize to a larger updating set.

2 Multi-sample Reconstruction Attack

Attack Definition. Our last attack, namely multi-sample reconstruction attack, aims at reconstructing the updating set. This attack can be considered as a generalization of the single-sample reconstruction attack, and a step towards the goal of reconstructing the training set of a black-box ML model. Formally, the attack is defined as follows:

where Dupdate={xupdate1,…,xupdate∣Dupdate∣}\mathcal{D}_{\it update}=\{x^{1}_{\it update},\dots,x^{|\mathcal{D}_{\it update}|}_{\it update}\} contains the samples used to update the model.

Methodology. The complexity of the task for reconstructing an updating set increases significantly when the updating set size grows from one to multiple. Our single-sample reconstruction attack (Section 4.2) uses AE to reconstruct a single sample. However, AE cannot generate a set of samples. In fact, directly predicting a set of examples is a very challenging task. Therefore, we rely on generative models which are able to generate multiple samples rather than a single one.

We first introduce the classical Generative Adversarial Networks (GANs) and point out why classical GANs cannot be used for our multi-sample reconstruction attack. Next, we propose our Conditional Best of Many GAN (CBM-GAN), a novel hybrid generative model and demonstrate how to use it to execute the multi-sample reconstruction attack.

Generative Adversarial Networks. Samples from a dataset are essentially samples drawn from a complex data distribution. Thus, one way to reconstruct the dataset Dupdate\mathcal{D}_{\it update} is to learn this complex data distribution and sample from it. This is the approach we adopt for our multi-sample reconstruction attack. Mainly, the adversary starts the attack by learning the data distribution of Dupdate\mathcal{D}_{\it update}, then she generates multiple samples from the learned distribution, which is equivalent to reconstructing the dataset Dupdate\mathcal{D}_{\it update}. In this work, we leverage the state-of-the-art generative model GANs, which has been demonstrated effective on learning a complex data distribution.

A GAN consists of a pair of ML models: a generator (G) and a discriminator (D). The generator G learns to transform a Gaussian noise vector z∼N(0,1)z\sim\mathcal{N}(0,1) to a data sample x^\hat{x},

such that the generated sample x^\hat{x} is indistinguishable from a true data sample. This is enabled by the discriminator D which is jointly trained. The generator G tries to fool the discriminator, which is trained to distinguish between samples from the Generator (G) and true data samples. The objective function maximized by GAN’s discriminator D is,

The GAN discriminator D is trained to output 1 (“true”) for real data and 0 (“false”) for fake data. On the other hand, the generator G maximizes:

Thus, G is trained to produce samples x^=G(z)\hat{x}=\text{G}(z) that are classified as “true” (real) by D.

However, our attack aims to reconstruct Dupdate\mathcal{D}_{\it update} for any given δ\delta, which the standard GAN does not support. Therefore, first, we change the GAN into a conditional model to condition its generated samples x^\hat{x} on the posterior difference δ\delta. Second, we construct our novel hybrid generative model CBM-GAN, by adding a new “Best Match” loss to reconstruct all samples inside the updating set accurately.

CBM-GAN. The decoder of our attack model is casted as our CBM-GAN’s generator (G). To enable this, we concatenate the noise vector zz and the latent vector μ\mu produced by our attack model’s encoder (with posterior different as input), and use it as CBM-GAN’s generator’s input, as in Conditional GANs . This allows our decoder to map the posterior difference δ\delta to samples in Dupdate\mathcal{D}_{\it update}.

However, Conditional GANs are severely prone to mode collapse, where the generator’s output is restricted to a limited subset of the distribution . To deal with this, we introduce a reconstruction loss. This reconstruction loss forces our GAN to cover all the modes of the distribution (set) of data samples used to update the model. However, it is unclear, given a posterior difference δ\delta and a noise vector zz pair, which sample in the data distribution we should force CBM-GAN to reconstruct. Therefore, we allow our GAN full flexibility in learning a mapping from posterior difference and noise vector zz pairs to data samples – this means we allow it to choose the data sample to reconstruct. We realize this using a novel “Best Match” based objective in the CBM-GAN formulation,

where x^∼G\hat{x}\sim\text{G} represents samples produced by our CBM-GAN given a latent vector μ\mu and noise sample zz. The first part of the LBM\mathcal{L}_{BM} objective is based on the standard MSE reconstruction loss and forces our CBM-GAN to reconstruct all samples in Dupdate\mathcal{D}_{\it update} as the error is summed across x∈Dupdatex\in\mathcal{D}_{\it update}. However, unlike the standard MSE loss, given a data sample x∈Dupdatex\in\mathcal{D}_{\it update}, the loss is based only on the generated sample x^\hat{x} which is closest to the data sample x∈Dupdatex\in\mathcal{D}_{\it update}. This allows CBM-GAN to reconstruct samples in Dupdate\mathcal{D}_{\it update} without having an explicit mapping from posterior difference and noise vector zz pairs to data samples, as only the “Best Match” is penalized. Finally, the discriminator D ensures that the samples x^\hat{x} are indistinguishable from the “true” samples of Dupdate\mathcal{D}_{\it update}.

Training of CBM-GAN. The training of the attack model AMSR\mathcal{A}_{\it MSR} is more complicated than previous attacks, hence we provide more details here. Similar to the previous attacks, the adversary starts the training by generating the training data as mentioned in Section 3. She then jointly trains her encoder and CBM-GAN with the posterior difference δshadow1⋯δshadowm\delta_{\it shadow}^{1}\cdots\delta_{\it shadow}^{m} as the inputs and samples inside their corresponding updating sets, i.e., Dshadowupdate1⋯Dshadowupdatem\mathcal{D}_{\it shadow}^{\it update^{1}}\cdots\mathcal{D}_{\it shadow}^{\it update^{m}} as the output. More concretely, for each posterior difference δshadowi\delta_{\it shadow}^{i}, she updates her attack model AMSR\mathcal{A}_{\it MSR} as follows:

The adversary sends the posterior difference δshadowi\delta_{\it shadow}^{i} to her encoder to get the latent vector μi\mu_{i}.

She then generates ∣Dshadowupdatei∣|\mathcal{D}_{\it shadow}^{\it update^{i}}| noise vectors.

To create generator’s input, she concatenates each of the noise vectors with the latent vector μi\mu_{i}.

On the input of the concatenated vectors, the CBM-GAN generates ∣Dshadowupdatei∣|\mathcal{D}_{\it shadow}^{\it update^{i}}| samples, i.e., each vector corresponds to each sample.

The adversary then calculates the generator loss as introduced by Equation 2, and uses it to update the generator and the encoder.

Finally, she calculates and updates the CBM-GAN’s discriminator according to Equation 1.

Clustering. CBM-GAN only provides a generator which learns the distribution of the samples in the updating set. However, to reconstruct the exact data samples in Dupdate\mathcal{D}_{\it update}, we need a final step assisted by machine learning clustering. In detail, we assume the adversary knows the cardinality of Dupdate\mathcal{D}_{\it update} as in Section 5.1. After CBM-GAN is trained, the adversary utilizes CBM-GAN’s generator to generate a large number of samples. She then clusters the generated samples into ∣Dupdate∣|\mathcal{D}_{\it update}| clusters. Here, the K-means algorithm is adopted to perform clustering where we set K to ∣Dupdate∣|\mathcal{D}_{\it update}|. In the end, for each cluster, the adversary calculates its centroid, and takes the nearest sample to the centroid as one reconstructed sample.

Figure 7 presents a schematic view of our multi-sample reconstruction attack’s methodology. The concrete architecture of CBM-GAN’s generator and discriminator for the three datasets used in this paper are listed in Appendix E.

Experimental Setup. We evaluate the multi-sample reconstruction attack on the updating set of size 100 and generate 20,000 samples for each updating set reconstruction with CBM-GAN. For the rest of the experimental settings, we follow the one mentioned in Section 5.1 except for evaluation metrics and baseline.

We use MSE between the updating and reconstructed data samples to measure the multi-sample reconstruction attack’s performance. We construct two baselines, namely Shadow-clustering and Label-average. For Shadow-clustering, we perform K-means clustering on the adversary’s shadow dataset. More concretely, we cluster the adversary’s shadow dataset into 100 clusters and take the nearest sample to the centroid of each cluster as one reconstructed sample. For Label-average, we calculate the MSE between each sample in the updating set and the average of the images with the same label in the adversary’s shadow dataset.

Results. In Figure 8, we first present some visualization of the intermediate result of our attack, i.e., the CBM-GAN’s output before clustering, on the CIFAR-10 dataset. For each randomly sampled image in the updating set, we show the 5 nearest reconstructed images with respect to MSE generated by CBM-GAN. As we can see, our attack model tries to generate images with similar characteristics to the original images. For instance, the 5 reconstructed images for the airplane image in 8(b) all show a blue background and a blurry version of the airplane itself. The similar result can be observed from the boat image in 8(a), the car image in 8(c), and the boat image in 8(d). It is also interesting to see that CBM-GAN provides different samples for the two different horse images in 8(b). The blurriness in the results is expected, due to the complex nature of the CIFAR-10 dataset and the weak assumptions for our adversary, i.e., access to black-box ML model.

We also quantitatively measure the performance of our intermediate results, by calculating the MSE between each image in the updating set and its nearest reconstructed sample. We refer to this as one-to-one match. Figure 9 shows for the CIFAR-10, MNIST, and Insta-NY datasets, we achieve 0.0283, 0.043 and 0.60 MSE, respectively. It is important to note that the adversary cannot perform one-to-one match as she does not have access to ground truth samples in the updating set, i.e., one-to-one match is an oracle.

Figure 9 shows the mean squared error of our full attack with clustering for all datasets. To match each of our reconstructed samples to a sample in Dupdate\mathcal{D}_{\it update}, we rely on the Hungarian algorithm . This guarantees that each reconstructed sample is only matched with one ground truth sample in Dupdate\mathcal{D}_{\it update} and vice versa. As we can see, our attack outperforms both baseline models on the CIFAR-10, MNIST and Insta-NY datasets (20%, 22%, and 25% performance gain for Shadow-clustering and 60.1%, 5.5% and 14% performance gain for Label-average, respectively). The different performance gain of our attack over the label-average baseline for different datasets is due to the different complexity of these datasets. For instance, all images inside MNIST have black background and lower variance within each class compared to the CIFAR-10 dataset. The different complexity results in some datasets having a more representative label-average, which leads to a lower performance gain of our attack over them.

These results show that our multi-sample reconstruction attack provides a more useful output than calculating the average from the adversary’s dataset. In detail, our attack achieves an MSE of 0.036 on the CIFAR-10 dataset, 0.051 on the MNIST dataset, and 0.64 on the Insta-NY dataset. As expected, the MSE of our final attack is higher than one-to-one match, i.e., the above mentioned intermediate results.

We further visualize our full attack’s result on the MNIST dataset. Figure 10 shows a sample of a full MNIST updating set reconstruction, i.e., the CBM-GAN’s reconstructed images for the 100 original images in an updating set. We observe that our attack model reconstructs diverse digits of each class that for most of the cases match the actual ground truth data very well. This suggests CBM-GAN is able to capture most modes in a data distribution well. Moreover, comparing the results of this attack (Figure 10) with the results of the single-sample reconstruction attack (Figure 5), we can see that this attack produces sharper images. This result is due to the discriminator of our CBM-GAN, as it is responsible for making the CBM-GAN’s output to look real, i.e., sharper in this case.

One limitation of our attack is that CBM-GAN’s sample generation and clustering are performed separately. In the future, we plan to combine them to perform an end-to-end training which may further boost our attack’s performance.

From all these results, we show that our attack does not generate a general representation of data samples affiliated with the same label, but tries to reconstruct images with similar characteristics as the images inside the updating set (as shown by the different shapes of the same numbers in Figure 10).

Relaxing The Knowledge of Updating Set Cardinality. One of the above attack’s main assumptions is the adversary’s knowledge of the updating set cardinality, i.e., ∣Dupdate∣|\mathcal{D}_{\it update}|. Next, we show how to relax this assumption. To recap, the adversary needs the updating set cardinality when updating her shadow model and clustering CBM-GAN’s output. We address the former by using updating sets of different cardinalities. For the latter, we use the silhouette score to find the optimal k for K-means, i.e., the most likely value of the target updating set’s cardinality. The silhouette score lies in the range between -1 and 1, it reflects the consistency of the clustering. Higher silhouette score leads to more suitable k.

Specifically, the adversary follows the previously presented methodology in Section 5.2 with the following modifications. First, instead of using updating sets with the same cardinality, the adversary uses updating sets with different cardinalities to update the shadow model. Second, after the adversary generates multiple samples from CBM-GAN, she uses the silhouette score to find the optimal k. The silhouette score is used here to identify the target model’s updating set cardinality from the different updating sets cardinalities used to update the shadow model.

We evaluate the effectiveness of this attack on all datasets. We use a target model updated with 100 samples and create our shadow updated models using updating sets with cardinality 10 and 100. Concretely, we update the shadow model half of the time with updating sets of cardinality 10 and the other half with cardinality 100.

Our evaluation shows that our attack consistently produces higher silhouette score -by at least 20%- for the correct cardinality in all cases. In another way, our method can always detect the right cardinality of the updating set in this setting. Moreover, the MSE for the final output of the attack only drops by 1.6%, 0.8%, and 5.6% for the Insta-NY, MNIST, and CIFAR-10 datasets, respectively.

Discussion

In this section, we analyze the effect of different hyperparameters of both the target and shadow models on our attacks’ performance. Furthermore, we investigate relaxing the threat model assumptions and discuss the limitations of our attacks.

Relaxing The Attacker Model Assumption. Our threat model has two main assumptions: Same data distribution for both target and shadow datasets and same structure for both target and shadow models. We relax the former by proposing data transferability attack and latter by model transferability attack.

Data Transferability. In this setting, we locally train and update the shadow model with a dataset which comes from a different distribution from the target dataset. For our experiments, we use Insta-NY as the target dataset and Insta-LA as the shadow dataset.

Table 1 depicts the evaluation results. As expected, the performance of our data transferability attacks drops; however, they are still significantly better than corresponding baseline models. For instance, the performance of the multi-sample reconstruction attack drops by 14% but is still 10% better than the baseline (see Figure 9). Moreover, the multi-sample label distribution attack’s accuracy (KL-divergence) only drops by 6.8% (18.9%) and 0% (63%), which is still significantly better than the baseline (see Figure 6) by 6.5x (2x) and 4.6x (4.8x) for updating set sizes of 10 and 100, respectively.

Model Transferablity. Now we relax the attacker’s knowledge on the target model’s architecture, i.e., we use different architectures for shadow and target models. In our experiments on Insta-NY, we use the same architecture mentioned previously in Section 4.1 for the target model, and remove one hidden layer and use half of the number of neurons in other hidden layers for the shadow model.

The performance drop of our model transferability attack is only less than 2% for all of our attacks, which shows that our attacks are robust against such changes in the model architectures. We observe similar results when repeating the experiment using different architectures and omit them for space restrictions.

Effect of The Probing Set Cardinality. We evaluate the performance of our attacks on CIFAR-10 when the probing set cardinality is 10, 100, 1,000, or 10,000. As our encoder’s input size relies on the probing set cardinality (see Section 3), we adjust its input layer size accordingly.

As expected, using a probing set of size 10 reduces the performance of the attacks. For instance, the single-sample label inference and reconstruction attacks’ performance drops by 9% and 71%, respectively. However, increasing the probing set cardinality from 100 to 1,000 or 10,000 has a limited effect (up to 3.5% performance gain). It is also important to mention that the computational requirement for our attacks increases with an increasing probing set cardinality, as the cardinality decides the size of the input layer for our attack models. In conclusion, using 100 samples for probing the target model is a suitable choice.

Effect of Target Model Hyperparameters. We now evaluate our attacks’ performance with respect to two hyperparameters of the target model.

Target Model’s Training Epochs Before Updating. We use the MNIST dataset to evaluate the multi-sample label distribution estimation attack’s performance on target models trained for 10, 20, and 50 epochs. For each setting, we update the model and execute our attack as mentioned in Section 5.1.

The experiments show that the difference in the attack’s performance for the different models is less than 2%. That is expected as gradients are not monotonically decreasing during the training procedure. In other words, information is not necessarily vanishing .

Target Model’s Updating Epochs. We train target and shadow models as introduced in Section 5.1 with the Insta-NY dataset, but we update the models using different number of epochs. More concretely, we update the models using from 2 to 10 epochs and evaluate the multi-sample label distribution estimation attack’s performance on the updated models.

We report the results of our experiments in Figure 11. As expected, the multi-sample label distribution estimation attack’s performance improves with the increase of the number of epochs used to update the model. For instance, the attack performance improves by 25.4 % when increasing the number of epochs used to update the model from 2 to 10.

Limitations of Our Attacks. For all of our attacks, we assume a simplified setting, in which, the target model is solely updated on new data. Moreover, we perform our attacks on updating sets of maximum cardinality of 100. In future work, we plan to further investigate a more complex setting, where the target model is updated using larger updating sets of both new and old data.

Possible Defenses

Adding Noise to Posteriors. All our attacks leverage posterior difference as the input. Therefore, to reduce our attacks’ performance, one could sanitize posterior difference. However, the model owner cannot directly manipulate the posterior difference, as she does not know with what or when the adversary probes her model. Therefore, she has to add noise to the posterior for each queried sample independently. We have tried adding noise sampled from a uniform distribution to the posteriors. Experimental results show that the performance for some of our attacks indeed drops to a certain degree. For instance, the single-sample label inference attack on the CIFAR-10 dataset drops by 17% in accuracy. However, the performance of our multi-sample reconstruction attack stays stable. One reason might be the noise vector zz is part of CBM-GAN’s input which makes the attack model more robust to the noisy input.

Differential Privacy. Another possible defense mechanism against our attacks is differentially private learning. Differential privacy can help an ML model learn its main tasks while reducing its memory on the training data. If differentially private learning schemes are used when updating the target ML model, this by design will reduce the performance of our attacks. However, it is also important to mention that depending on the privacy budget for differential privacy, the utility of the model can drop significantly.

We leave an in-depth exploration of effective defense mechanisms against our attacks as a future work.

Related Works

Membership Inference. Membership inference aims at determining whether a data sample is inside a dataset. It has been successfully performed in various settings, such as biomedical data and location data . Shokri et al. propose the first membership inference attack against machine learning models. In this attack, an adversary’s goal is to determine whether a data sample is in the training set of a black-box ML model. To mount this attack, the adversary relies on a binary machine learning classifier which is trained with the data derived from shadow models (similar to our attacks). More recently, multiple membership inference attacks have been proposed with new attacking techniques or targeting on different types of ML models .

In theory, membership inference attack can be used to reconstruct the dataset, similar to our reconstruction attacks. However, it is not scalable in the real-world setting as the adversary needs to obtain a large-scale dataset which includes all samples in the target model’s training set. Though our two reconstruction attacks are designed specifically for the online learning setting, we believe the underlying techniques we propose, i.e., pretrained decoder from a standard autoencoder and CBM-GAN, can be further extended to reconstruct datasets from black-box ML models in other settings.

Model Inversion. Fredrikson et al. propose model inversion attack first on biomedical data. The goal of model inversion is to infer some missing attributes of an input feature vector based on the interaction with a trained ML model. Later, other works generalize the model inversion attack to other settings, e.g.,, reconstructing recognizable human faces . As pointed out by other works , model inversion attack reconstructs a general representation of data samples affiliated with certain labels, while our reconstruction attacks target on specific data samples used in the updating set.

Model Stealing. Another related line of work is model stealing. Tramèr et al. are among the first to introduce the model stealing attack against black-box ML models. In this attack, an adversary tries to learn the target ML model’s parameters. Tramèr et al. propose various attacking techniques including equation-solving and decision tree path-finding. The former has been demonstrated to be effective on simple ML models, such as logistic regression, while the latter is designed specifically for decision trees, a class of machine learning classifiers. Moreover, relying on an active learning based retraining strategy, the authors show that it is possible to steal an ML model even if the model only provides the label instead of posteriors as the output. More recently, Orekondy et al. propose a more advanced attack on stealing the target model’s functionality and show that their attack is able to replicate a mature commercial machine learning API. In addition to model parameters, several works concentrate on stealing ML models’ hyperparameters .

Besides the above, there exist a wide range of other attacks and defenses on machine learning models

Conclusion

Large-scale data being generated at every second turns ML model training into a continuous process. In consequence, a machine learning model queried with the same set of data samples at two different time points will provide different results. In this paper, we investigate whether these different model outputs can constitute a new attack surface for an adversary to infer information of the dataset used to perform model update. We propose four different attacks in this surface all of which follow a general encoder-decoder structure. The encoder encodes the difference in the target model’s output before and after being updated, and the decoder generates different types of information regarding the updating set.

We start by exploring a simplified case when an ML model is only updated with one single data sample. We propose two different attacks for this setting. The first attack shows that the label of the single updating sample can be effectively inferred. The second attack utilizes an autoencoder’s decoder as the attack model’s pretrained decoder for single-sample reconstruction.

We then generalize our attacks to the case when the updating set contains multiple samples. Our multi-sample label distribution estimation attack trained following a KL-divergence loss is able to infer the label distribution of the updating set’s data samples effectively. For the multi-sample reconstruction attack, we propose a novel hybrid generative model, namely CBM-GAN, which uses a “Best Match’ loss in its objective function. The “Best Match” loss directs CBM-GAN’s generator to reconstruct each sample in the updating set. Quantitative and qualitative results show that our attacks achieve promising performance.

Acknowledgments

We thank the anonymous reviewers, and our shepherd, David Evans, for their helpful feedback and guidance.

The research leading to these results has received funding from the European Research Council under the European Union’s Seventh Framework Programme (FP7/2007-2013)/ ERC grant agreement no. 610150-imPACT.

References

Appendix A Target Models Architecture

Appendix B Encoder Architecture

Encoder architecture: \displaystyle\texttt{\delta}\rightarrow\texttt{FullyConnected(128)} FullyConnected(6464) \displaystyle\rightarrow\texttt{\mu} Here, μ\mu denotes the latent vector which serves as the input for our decoder. Furthermore, we use LeakyReLU as our encoder’s activation function and apply dropout on both layers for regularization.

Appendix C Single-sample Label Inference Attack’s Decoder Architecture

Appendix D Single-sample Reconstruction Attack

AE’s encoder architecture for MNIST and CIFAR-10: \displaystyle\texttt{Sample}\rightarrow\texttt{conv2d(k_{1},,s_{1})} max(22) conv2d(k2k_{2}, s2s_{2}) max(22) FullyConnected(f1f_{1}) FullyConnected(f2f_{2}) →μAE\displaystyle\rightarrow\mu_{\it AE} AE’s encoder architecture for Insta-NY: Sample→FullyConnected(64)\displaystyle\texttt{Sample}\rightarrow\texttt{FullyConnected(64)} FullyConnected(32) FullyConnected(16) FullyConnected(16) →μAE\displaystyle\rightarrow\mu_{\it AE} Here, μAE\mu_{\it AE} is the latent vector output of the encoder. Moreover, kik_{i}, sis_{i}, and fif_{i} represent the kernel size, number of filters, and number of units in the iith layer. The concrete values of these hyperparameters depend on the target dataset, we present our used values in Table 2. We adopt ReLU as the activation function for all layers for the MNIST and CIFAR-10 encoders. For the Insta-NY decoder, we use ELU as the activation function for all layers except for the last one. Finally, we apply dropout after the first fully connected layer for MNIST and CIFAR-10. For Insta-NY, we apply dropout and batch normalization for the first three fully connected layers.

D.2 AE’s Decoder Architecture

Autoencoder’s decoder architecture for MNIST and CIFAR-10: \displaystyle\mu_{\it AE}\rightarrow\texttt{FullyConnected(f_{1}^{\prime})} FullyConnected(f2′f_{2}^{\prime}) ConvTranspose2d(k1′k_{1}^{\prime}, s1′s_{1}^{\prime}) ConvTranspose2d(k2′k_{2}^{\prime}, s2′s_{2}^{\prime}) ConvTranspose2d(k3′k_{3}^{\prime}, s3′s_{3}^{\prime}) →Sample\displaystyle\rightarrow\texttt{Sample} Autoencoder’s decoder architecture for Insta-NY: μAE→FullyConnected(16)\displaystyle\mu_{\it AE}\rightarrow\texttt{FullyConnected(16)} FullyConnected(32) FullyConnected(64) FullyConnected(168) →Sample\displaystyle\rightarrow\texttt{Sample} Here, ConvTranspose2d(k’,s’) denotes a 2-dimension transposed convolution layer with kernel size k′×k′k^{\prime}\times k^{\prime} and s′s^{\prime} filters, and fi′f_{i}^{\prime} specifies the number of units in the iith fully connected layer. The concrete values of these hyperparameters are presented in Table 2. For MNIST and CIFAR-10 decoders, we again use ReLU as the activation function for all layers except for the last one where we adopt tanh. For the Insta-NY decoder, we adopt ELU for all layers except for the last one. We also apply dropout after the last fully connected layer for regularization for MNIST and CIFAR-10, and dropout and batch normalization on the first three fully connected layers for Insta-NY.

Appendix E Multi-sample Reconstruction Attack’s Decoder Architecture

CBM-GAN’s generator architecture for MNIST: μ,z→FullyConnected(2048)\displaystyle\mu,z\rightarrow\texttt{FullyConnected(2048)} FullyConnected(2048) FullyConnected(2048) FullyConnected(784) →Sample\displaystyle\rightarrow\texttt{Sample} CBM-GAN’s discriminator architecture for MNIST: μ,z→FullyConnected(1024)\displaystyle\mu,z\rightarrow\texttt{FullyConnected(1024)} FullyConnected(512) FullyConnected(256) FullyConnected(1) Sigmoid→\displaystyle\texttt{Sigmoid}\rightarrow {1,0} CBM-GAN’s generator architecture for CIFAR-10: μ,z→conv2d(2, 512)\displaystyle\mu,z\rightarrow\texttt{conv2d(2, 512)} conv2d(4, 256) conv2d(4, 128) conv2d(4, 64) conv2d(4, 3) →Sample\displaystyle\rightarrow\texttt{Sample} CBM-GAN’s discriminator architecture for CIFAR-10: μ,z→conv2d(2, 64)\displaystyle\mu,z\rightarrow\texttt{conv2d(2, 64)} conv2d(4, 128) conv2d(4, 256) conv2d(4, 512) conv2d(4, 1) Sigmoid→\displaystyle\texttt{Sigmoid}\rightarrow {1,0} CBM-GAN’s generator architecture for Insta-NY: μ,z→FullyConnected(512)\displaystyle\mu,z\rightarrow\texttt{FullyConnected(512)} FullyConnected(512) FullyConnected(256) FullyConnected(168) →Sample\displaystyle\rightarrow\texttt{Sample} CBM-GAN’s discriminator architecture for Insta-NY: μ,z→FullyConnected(512)\displaystyle\mu,z\rightarrow\texttt{FullyConnected(512)} FullyConnected(256) FullyConnected(128) FullyConnected(1) Sigmoid→\displaystyle\texttt{Sigmoid}\rightarrow {1,0} Here, for both generators and discriminators, Sigmoid is the Sigmoid function, batch normalization is applied on the output of each layer except the last layer, and LeakyReLU is used as the activation function for all layers except the last one, which uses tanh.