[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118383-en":3,"doc-seo-118383-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118383,1099514067415,"Rowan","https://ap-avatar.wpscdn.com/avatar/100002539d78ffe74a7?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779092875211072502",8,"Research & Report","Privacy Attacks and Defenses under Security Threats in Machine Learning - Thesis for PhD","Machine learning is widely adopted, yet real-world privacy and security threats expose vulnerabilities in deployed models. Privacy attacks enable adversaries to recover training data, infer membership, and clone models without authentication, while security attacks disrupt model functionality and behavior. This thesis examines how privacy and security threats interact, focusing on performance changes in privacy attacks and defenses when security attacks are present. It shows adversarial examples can amplify reconstruction and privacy leakage, proposes a universal privacy attack framework bridging label-only and confidence-based methods, introduces a data-poisoning defense leveraging attacker security weaknesses, and presents a benign privacy-attack-based mechanism to detect model stealing via output fingerprinting.","Privacy Attacks and Defenses under  \nSecurity Threats in Machine Learning by Shuai Zhou  \nThesis submitted in fulfilment of the requirements for the degree of  \nDoctor of Philosophy  \nunder the supervision of Tianqing Zhu & Dayong Ye  \nUniversity of Technology Sydney  \nFaculty of Engineering & Information Technology February 2024  \nCERTIFICATE OF ORIGINAL AUTHORSHIP  \nCompsity ofesis isrShnollcoyilencogymyeSo,tyrk Engineeless othenwgisande reformatnced on aackel-  \n, Shuai Zhou declare that this thesis is submitted in partial ful􀀂lment  \nof the requirements for the award of Doctor of Philosophy, in the School  \nedged. In addition, I certify that all information sources and literature used are indicated in the thesis.  \nThis document has not been submitted for quali􀀂cations at any other academic institution. This research is supported by the Australian Government Research Training Program.  \nProduction Note:  \nSIGNATURE:  Signature removed prior to publication.   \nDATE: 28th February, 2024  \nPLACE: Sydney, Australia  \nABSTRACT  \nMachine learning has been increasingly adopted across various domains due to  \nits outstanding performance. However, machine learning models exhibit some vulnerabilities against threats in the real world, including privacy risks and security concerns. In terms of privacy risks, malicious users can steal the private information of other users or model owners, including recovering training data, inferring membership, and cloning the trained model without authentication. In terms of security, the functionality of machine learning models might be disrupted by malicious users.  \nBoth types of attacks pose challenges to the widespread deployment of machine learning models. However, these attacks are often studied separately, and their relationship isnot well understood. To gain a better understanding of threats in machine learning, this thesis explores the interaction between privacy and security threats, especially the change in performance of privacy attacks and defenses when security attacks are present. Speci􀀂cally, the contributions can be summarized as follows:  \n􀂕 This thesis reveals that adversarial examples have the potential to enhance thereconstruction of private training data, implying that security vulnerabilities would amplify the privacy leakages in machine learning. This insight enables a more precise assessment of privacy threats.  \n􀂕 We emphasize that adversarial attacks can escalate the privilege of attackers targeting compromising privacy. We propose a universal privacy attack framework that enhances the existing label-only attacks by recovering the con􀀂dence vectors. This framework bridges the gap between label-only and con􀀂dence-based attacks.  \n􀂕 We introduce an innovative defense to prevent the reconstruction of private data, which incorporates data poisoning techniques as a defensive strategy. This strategy leverages the security vulnerabilities inherent in the models of attackers to diminish their performance, thereby preventing privacy leakage. This approach represents a benign application of security attacks.  \n􀂕 We investigate the benign use of privacy attacks, leading to a defense mechanism against model stealing attacks. By exploiting model inversion attacks for data reconstruction, we can uncover the hidden patterns in the model's outputs, effectively creating a unique 􀀂ngerprint for the model. This method allows us to detect the model stealing behaviors based on normal examples, eliminating the need for adversarial examples.  \nDEDICATION  \nTo my family and supervisors, whose support and encouragement have been the foundation during  \nmyjourney.  \nACKNOWLEDGMENTS  \nFirstly, I am deeply grateful to my supervisor, Professor Tianqing Zhu, for her  \ninvaluable guidance and patient mentorship that enabled me to successfully  \ncomplete my Ph.D. studies. Her expertise and wisdom have been instrumental in shaping my research.  \nMoreover, I extend my gratitude to my co-supervisor, Dr. D","cbCaignzwxKuElE2","https://ap.wps.com/l/cbCaignzwxKuElE2","pdf",6722159,1,202,"English","en",105,"# Abstract\n## Privacy risks in machine learning\n## Security threats and disruption\n## Interaction between privacy and security attacks\n## Thesis contributions\n## Publications","[{\"question\":\"What privacy risks does the thesis focus on in machine learning?\",\"answer\":\"The thesis targets privacy attacks that recover training data, infer membership, and clone trained models without authentication.\"},{\"question\":\"How does the thesis connect privacy attacks with security threats?\",\"answer\":\"It studies how the presence of security attacks changes the performance of privacy attacks and defenses, clarifying the interaction between both threat types.\"},{\"question\":\"What defenses does the thesis propose to prevent privacy leakage and model stealing?\",\"answer\":\"It introduces a defense using data poisoning to hinder private-data reconstruction, and it proposes a model-stealing detection method based on benign privacy attacks and output-based fingerprinting.\"}]","Privacy Attacks and Defenses under Security Threats in Machine Learning - Thesis for PhD | PDF",1785683369,509,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"privacy-attacks-and-defenses-under-security-threats-in-machine-learning-thesis-for-phd","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/privacy-attacks-and-defenses-under-security-threats-in-machine-learning-thesis-for-phd/118383/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What privacy risks does the thesis focus on in machine learning?","Question",{"text":75,"@type":76},"The thesis targets privacy attacks that recover training data, infer membership, and clone trained models without authentication.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the thesis connect privacy attacks with security threats?",{"text":80,"@type":76},"It studies how the presence of security attacks changes the performance of privacy attacks and defenses, clarifying the interaction between both threat types.",{"name":82,"@type":73,"acceptedAnswer":83},"What defenses does the thesis propose to prevent privacy leakage and model stealing?",{"text":84,"@type":76},"It introduces a defense using data poisoning to hinder private-data reconstruction, and it proposes a model-stealing detection method based on benign privacy attacks and output-based fingerprinting.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]