[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118705-en":3,"doc-seo-118705-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118705,7971461741311,"Ophelia","https://ap-avatar.wpscdn.com/avatar/74000253aff267980c6?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779345379180704826",8,"Research & Report","A Survey of Privacy Attacks in Machine Learning","Machine learning’s expanding adoption increases the urgency of understanding security and privacy implications, especially when models are treated as black boxes. This survey analyzes over 40 papers from the past seven years to address privacy attacks against machine learning. It proposes an attack taxonomy and a threat model that classifies attacks by adversarial knowledge and targeted assets, then compares attacked models and datasets across approaches. Finally, it examines likely sources of privacy leakage and summarizes common defenses, including membership inference and related risks.","View metadata, citation and similar [papers at ](papers at core.ac.uk)[core.ac.uk](papers at core.ac.uk) brought to you by CORE  \n[provided by](provided by arXiv.org)[ arXiv.org](provided by arXiv.org) e-Print Archive  \narXiv :2007 .07646v 1 [ cs .CR] 15 Jul 2020  \nA Survey of Privacy Attacks in Machine Learning  \nMARIA RIGAKI, Czech Technical University in Prague SEBASTIAN GARCIA, Czech Technical University in Prague  \nAs machine learning becomes more widely used, the need to study its implications in security and privacy becomes more urgent. Research on the security aspects of machine learning, such as adversarial attacks, has received a lot of focus and publicity, but privacy related attacks have received less attention from the research community. Although there is a growing body of work in the area, there is yet no extensive analysis of privacy related attacks. To contribute into this research line we analyzed more than 40 papers related to privacy attacks against machine learning that have been published during the past seven years. Based on this analysis, an attack taxonomy is proposed together with a threat model that allows the categorization of the different attacks based on the adversarial knowledge and the assets under attack. In addition, a detailed analysis of the different attacks is presented, including the models under attack and the datasets used, as well as the common elements and main differences between the approaches under the defined threat model. Finally, we explore the potential reasons for privacy leaks and present an overview of the most common proposed defenses.  \nCCS Concepts: • Computing methodologies → Machine learning; • Security and privacy;  \nAdditional Key Words and Phrases: privacy, machine learning, membership inference, property inference, model extraction, reconstruction  \n1 INTRODUCTION  \nFueled by large amounts of available data and hardware advances, machine learning has experienced tremendous growth, both in terms of academic research and of real world applications. At the same time, the impact of machine learning in security, privacy, and fairness is receiving increasing attention. In terms of privacy, our personal data are being harvested by almost every online service and are used to train models that power machine learning based applications. When these applications are presented as black-box models, it is expected that they should not reveal information about the data used for their training. If a model was trained using sensitive data such as location, health records, or identity information, then an attack that allows an adversary to extract this information is highly undesirable. At the same time, if private data have been used without their owners’ consent, the same type of attack could be used as a way to determine unauthorized use and thus work in favor of the user’s privacy.  \nThe security of machine learning and the impacts of adversarial attacks in the performance of the models have been widely studied in the community, with several surveys highlighting the major advances in the area [6, 57, 75, 98] . Some of these surveys also provide a partial coverage on the topic of privacy attacks, but there is no overall survey that considers privacy attacks against machine learning models as its main focus. This paper is, as far as we know, the first comprehensive survey of privacy-related attacks against machine learning. This survey focuses on leaks of information from the training data and also leaks of information about the models themselves. In this sense, an attack that extracts information about the model structure is, strictly speaking, an attack against model confidentiality. The decision to include model extraction attacks was made because (i) these attacks are an important part of the threat model presented in Section 3 and (ii) because in the existing literature, attacks against model confidentiality are usually grouped together with privacy attacks [6, 75] . In additi","cbCail93GSMhhp6S","https://ap.wps.com/l/cbCail93GSMhhp6S","pdf",1103943,1,29,"English","en",105,"# Introduction\n# Threat Model and Attack Taxonomy\n## Attacks, Models, and Datasets\n## Privacy Leakage Causes and Defenses","[{\"question\":\"What gap does the survey address in privacy research for machine learning?\",\"answer\":\"It targets the lack of an extensive, comprehensive analysis of privacy-related attacks against machine learning models as a main focus.\"},{\"question\":\"How does the survey organize different privacy attacks?\",\"answer\":\"It proposes an attack taxonomy and a threat model, categorizing attacks based on adversarial knowledge and the assets being attacked.\"},{\"question\":\"What does the survey include in its analysis of privacy attacks?\",\"answer\":\"It provides detailed comparisons of the attacks, including the models under attack, datasets used, and the common elements and key differences among approaches under the defined threat model.\"}]","A Survey of Privacy Attacks in Machine Learning | PDF",1785684989,73,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"a-survey-of-privacy-attacks-in-machine-learning","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-survey-of-privacy-attacks-in-machine-learning/118705/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04","2026-08-02",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What gap does the survey address in privacy research for machine learning?","Question",{"text":76,"@type":77},"It targets the lack of an extensive, comprehensive analysis of privacy-related attacks against machine learning models as a main focus.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the survey organize different privacy attacks?",{"text":81,"@type":77},"It proposes an attack taxonomy and a threat model, categorizing attacks based on adversarial knowledge and the assets being attacked.",{"name":83,"@type":74,"acceptedAnswer":84},"What does the survey include in its analysis of privacy attacks?",{"text":85,"@type":77},"It provides detailed comparisons of the attacks, including the models under attack, datasets used, and the common elements and key differences among approaches under the defined threat model.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":46,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]