• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

针对基因组数据机器学习的成员推理攻击的差分隐私保护。

Differential Privacy Protection Against Membership Inference Attack on Machine Learning for Genomic Data.

机构信息

Department of Computer and Informatics Sciences, Temple University, Philadelphia, PA 19122, USA.

出版信息

Pac Symp Biocomput. 2021;26:26-37.

PMID:33691001
Abstract

Machine learning is powerful to model massive genomic data while genome privacy is a growing concern. Studies have shown that not only the raw data but also the trained model can potentially infringe genome privacy. An example is the membership inference attack (MIA), by which the adversary can determine whether a specific record was included in the training dataset of the target model. Differential privacy (DP) has been used to defend against MIA with rigorous privacy guarantee by perturbing model weights. In this paper, we investigate the vulnerability of machine learning against MIA on genomic data, and evaluate the effectiveness of using DP as a defense mechanism. We consider two widely-used machine learning models, namely Lasso and convolutional neural network (CNN), as the target models. We study the trade-off between the defense power against MIA and the prediction accuracy of the target model under various privacy settings of DP. Our results show that the relationship between the privacy budget and target model accuracy can be modeled as a log-like curve, thus a smaller privacy budget provides stronger privacy guarantee with the cost of losing more model accuracy. We also investigate the effect of model sparsity on model vulnerability against MIA. Our results demonstrate that in addition to prevent overfitting, model sparsity can work together with DP to significantly mitigate the risk of MIA.

摘要

机器学习在对大规模基因组数据进行建模方面具有强大的功能,而基因组隐私是一个日益受到关注的问题。研究表明,不仅原始数据,而且训练后的模型都有可能侵犯基因组隐私。一个例子是成员推断攻击(MIA),通过这种攻击,对手可以确定特定记录是否包含在目标模型的训练数据集中。差分隐私(DP)已被用于通过扰动模型权重来抵御 MIA,并提供严格的隐私保证。在本文中,我们研究了机器学习在基因组数据上对 MIA 的脆弱性,并评估了使用 DP 作为防御机制的有效性。我们考虑了两种广泛使用的机器学习模型,即 Lasso 和卷积神经网络(CNN),作为目标模型。我们研究了在 DP 的各种隐私设置下,针对 MIA 的防御能力与目标模型准确性之间的权衡。我们的结果表明,隐私预算与目标模型准确性之间的关系可以建模为对数曲线,因此较小的隐私预算可以提供更强的隐私保证,代价是损失更多的模型准确性。我们还研究了模型稀疏性对模型对 MIA 的脆弱性的影响。我们的结果表明,除了防止过拟合之外,模型稀疏性还可以与 DP 一起显著降低 MIA 的风险。

相似文献

1
Differential Privacy Protection Against Membership Inference Attack on Machine Learning for Genomic Data.针对基因组数据机器学习的成员推理攻击的差分隐私保护。
Pac Symp Biocomput. 2021;26:26-37.
2
Deep Neural Network Quantization Framework for Effective Defense against Membership Inference Attacks.用于有效防御成员推理攻击的深度神经网络量化框架
Sensors (Basel). 2023 Sep 7;23(18):7722. doi: 10.3390/s23187722.
3
Differential privacy under dependent tuples-the case of genomic privacy.相依元组下的差分隐私-基因组隐私案例。
Bioinformatics. 2020 Mar 1;36(6):1696-1703. doi: 10.1093/bioinformatics/btz837.
4
Inference attacks against differentially private query results from genomic datasets including dependent tuples.针对包含依赖元组的基因组数据集的差分隐私查询结果的推理攻击。
Bioinformatics. 2020 Jul 1;36(Suppl_1):i136-i145. doi: 10.1093/bioinformatics/btaa475.
5
Exploring the Relationship Between Privacy and Utility in Mobile Health: Algorithm Development and Validation via Simulations of Federated Learning, Differential Privacy, and External Attacks.探索移动健康中隐私与效用的关系:通过联邦学习、差分隐私和外部攻击的模拟算法开发和验证。
J Med Internet Res. 2023 Apr 20;25:e43664. doi: 10.2196/43664.
6
Defense against membership inference attack in graph neural networks through graph perturbation.通过图扰动防御图神经网络中的成员推理攻击
Int J Inf Secur. 2023;22(2):497-509. doi: 10.1007/s10207-022-00646-y. Epub 2022 Dec 16.
7
MemberShield: A framework for federated learning with membership privacy.成员护盾:一种具有成员隐私性的联邦学习框架。
Neural Netw. 2025 Jan;181:106768. doi: 10.1016/j.neunet.2024.106768. Epub 2024 Oct 1.
8
Mitigating Membership Inference in Deep Survival Analyses with Differential Privacy.通过差分隐私减轻深度生存分析中的成员推理
Proc (IEEE Int Conf Healthc Inform). 2023 Jun;2023:81-90. doi: 10.1109/ichi57859.2023.00022. Epub 2023 Dec 11.
9
mDARTS: Searching ML-Based ECG Classifiers Against Membership Inference Attacks.mDARTS:针对成员推理攻击搜索基于机器学习的心电图分类器
IEEE J Biomed Health Inform. 2025 Jan;29(1):177-187. doi: 10.1109/JBHI.2024.3481505. Epub 2025 Jan 7.
10
AnomiGAN: Generative Adversarial Networks for Anonymizing Private Medical Data.AnomiGAN:用于匿名化私人医疗数据的生成对抗网络。
Pac Symp Biocomput. 2020;25:563-574.

引用本文的文献

1
Genomic privacy and security in the era of artificial intelligence and quantum computing.人工智能与量子计算时代的基因组隐私与安全
Discov Comput. 2025;28(1):108. doi: 10.1007/s10791-025-09627-w. Epub 2025 Jun 6.
2
Addressing contemporary threats in anonymised healthcare data using privacy engineering.利用隐私工程应对匿名医疗保健数据中的当代威胁。
NPJ Digit Med. 2025 Mar 6;8(1):145. doi: 10.1038/s41746-025-01520-6.
3
Federated privacy-protected meta- and mega-omics data analysis in multi-center studies with a fully open-source analytic platform.
在多中心研究中,使用完全开源的分析平台进行联合隐私保护的元组学和宏组学数据分析。
PLoS Comput Biol. 2024 Dec 9;20(12):e1012626. doi: 10.1371/journal.pcbi.1012626. eCollection 2024 Dec.
4
Federated Learning in Glaucoma: A Comprehensive Review and Future Perspectives.青光眼领域的联邦学习:全面综述与未来展望
Ophthalmol Glaucoma. 2025 Jan-Feb;8(1):92-105. doi: 10.1016/j.ogla.2024.08.004. Epub 2024 Aug 29.
5
A Survey on Differential Privacy for Medical Data Analysis.医学数据分析中的差分隐私研究
Ann Data Sci. 2023 Jun 10:1-15. doi: 10.1007/s40745-023-00475-3.
6
Secure federated learning for Alzheimer's disease detection.用于阿尔茨海默病检测的安全联邦学习
Front Aging Neurosci. 2024 Mar 7;16:1324032. doi: 10.3389/fnagi.2024.1324032. eCollection 2024.
7
Assessing transcriptomic reidentification risks using discriminative sequence models.使用判别序列模型评估转录组再识别风险。
Genome Res. 2023 Jul;33(7):1101-1112. doi: 10.1101/gr.277699.123. Epub 2023 Aug 4.
8
Privacy-aware estimation of relatedness in admixed populations.混合人群中具有隐私意识的亲缘关系估计。
Brief Bioinform. 2022 Nov 19;23(6). doi: 10.1093/bib/bbac473.
9
A Novel Attention-Mechanism Based Cox Survival Model by Exploiting Pan-Cancer Empirical Genomic Information.基于泛癌经验基因组信息利用的新型注意力机制 Cox 生存模型。
Cells. 2022 Apr 22;11(9):1421. doi: 10.3390/cells11091421.
10
A Sequence Obfuscation Method for Protecting Personal Genomic Privacy.一种用于保护个人基因组隐私的序列混淆方法。
Front Genet. 2022 Apr 13;13:876686. doi: 10.3389/fgene.2022.876686. eCollection 2022.