arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

代码中毒属性推理攻击

Code-Poisoning Property Inference Attacks

Xukun Luan, Yuhui Gong, Gang Zhang, Zixuan Huang, Yuanguo Bi, Xuesong Li, Jinyan Liu

arXiv 2607.15970首次发表:更新:

发表机构

School of Computer Science and Technology, Beijing Institute of Technology; School of Computer Science and Engineering, Northeastern University(计算机科学与技术学院,北京理工大学; 计算机科学与工程学院,东北大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对机器学习模型训练数据隐私泄露问题,提出代码中毒属性推理攻击(CPPIA),克服现有工作局限。通过恶意代码提供者使数据持有者下载中毒代码训练模型,对手借此嵌入属性查询模型泄露隐私,该方法攻击准确率高、计算轻量,评估证明其通用性和有效性。

AI 中文摘要

蓬勃发展的代码托管平台和编码代理使初学者即使拥有私有数据也能利用现有代码快速构建定制机器学习(ML)模型。ML模型的训练数据常被视为私有财产,面临信息泄露风险。属性推理攻击(PIA)旨在暴露训练集的全局属性信息。本文提出代码中毒属性推理攻击(CPPIA),克服了现有工作的四个局限。考虑恶意代码提供者,数据持有者下载中毒代码后用私有数据训练模型并向公众发布仅标签的API,对手在训练时将属性嵌入秘密样本并随后查询训练模型来泄露隐私。CPPIA攻击准确率达100%且不降低模型准确率,计算轻量级且无需影子模型。通过四个数据集、八个模型架构、十八个属性及三种防御机制评估了攻击性能,证明了CPPIA的通用性和有效性。

英文摘要

The flourishing code hosting platforms and coding agents enable even beginners with private data to build tailored Machine Learning (ML) models using available code quickly. The training data for ML models, often regarded as private property (e.g., clinical records, transaction information), is at significant risk of information leakage. Property Inference Attacks (PIAs), as a significant type of privacy attack, aim to expose global property information of the training set. In this paper, we present Code-Poisoning Property Inference Attack (CPPIA), the first code-level PIA, which overcomes four limitations of existing works: insufficient attack performance, severe degradation of model accuracy, high computational overhead, and failure under defenses. We consider malicious code providers from code hosting platforms (GitHub) and coding agents (Codex). Upon downloading the poisoned code, data holders train models with their private data without professional auditing, subsequently releasing label-only APIs to the public. The adversary embeds the properties into secret samples during training and queries the trained model on these samples later to leak privacy. CPPIA offers 100\% attack accuracy without degrading model accuracy. It is also computationally lightweight and requires no shadow models. We evaluate the attack performance across four datasets, eight model architectures, eighteen properties, and under three defense mechanisms, demonstrating the universality and effectiveness of CPPIA.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑