Anli Yan

dblp:257/9823 · DBLP profile ↗
← Back
5ranked-venue papers in the field
2as first author
5since 2021 · last 2023
0000-0002-2854-2931ORCID · corroborated

Domains — venue-derived; a paper can count in several

Other / Interdisciplinary · 3 (1 first)Knowledge Engineering, Semantic Web & Information Systems · 2 (1 first)
YearPublicationVenuePosition
2023 Explanation leaks: Explanation-guided model extraction attacks
Anli Yan, Teng Huang 0001, Lishan Ke, Xiaozhang Liu, Qi Chen 0024, Changyu Dong
Inf. Sci.1
2022 DPCL: Contrastive representation learning with differential privacy
abstract
With the proliferation of unlabeled data, increasing efforts have been devoted to unsupervised learning. As one of the most representative branches of unsupervised learning, contrastive learning has made great progress with its high efficiency. Unfortunately, privacy threats to contrastive learning have become sophisticated, making it imperative to develop effective technologies that can deal with such threats. To alleviate the privacy issue in contrastive learning, we propose some novel techniques based on differential privacy, which aim at reducing the high sensitivity of gradient in the private training caused by interactive contrastive learning. Specifically, we add differentially private protection to the connection point related to different per-example gradients, which decreases the sensitivity of the gradients significantly. Our experiments on SimCLR and the Barlow Twins show that our approach is superior since it is more accurate while maintaining the same level of privacy protection.
Anli Yan, Di Wu 0056, Taoyu Zhu, Teng Huang 0001, Xuandi Luo
Int. J. Intell. Syst.2
2022 Towards explainable model extraction attacks
abstract
One key factor able to boost the applications of artificial intelligence (AI) in security-sensitive domains is to leverage them responsibly, which is engaged in providing explanations for AI. To date, a plethora of explainable artificial intelligence (XAI) has been proposed to help users interpret model decisions. However, given its data-driven nature, the explanation itself is potentially susceptible to a high risk of exposing privacy. In this paper, we first show that the existing XAI is vulnerable to model extraction attacks and then present an XAI-aware dual-task model extraction attack (DTMEA). DTMEA can attack a target model with explanation services, that is, it can extract both the classification and explanation tasks of the target model. More specifically, the substitution model extracted by DTMEA is a multitask learning architecture, consisting of a sharing layer and two task-specific layers for classification and explanation. To reveal which explanation technologies are more vulnerable to expose privacy information, we conduct an empirical evaluation of four major explanation types in the benchmark data set. Experimental results show that the attack accuracy of DTMEA outperforms the predicted-only method with up to 1.25%, 1.53%, 9.25%, and 7.45% in MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100, respectively. By exposing the potential threats on explanation technologies, our research offers the insights to develop effective tools that are able to trade off security-sensitive relationships.
Anli Yan, Ruitao Hou, Xiaozhang Liu, Hongyang Yan, Teng Huang 0001, Xianmin Wang
Int. J. Intell. Syst.1
2022 Sender anonymity: Applying ring signature in gateway-based blockchain for IoT is not enough
Arthur Sandor Voundi Koe, Shan Ai, Anli Yan, Qi Chen 0024, Kanghua Mo, Wanqing Jie, Shiwen Zhang 0004
Inf. Sci.4
2021 Querying little is enough: Model inversion attack via latent information
abstract
As machine learning (ML) technologies evolve, various online intelligent services use ML models to provide predictions. Unfortunately, attackers can obtain the private information of the model by interacting with the online service, namely model inversion attack (MIA). However, MIA requires large data sets to be transferred to an online service to obtain the predictive value of the inference model. Besides, the huge transmission may cause the administrator's active defense. To overcome this drawback, we propose a novel MIA scheme, which leverages latent information extracted by an auxiliary neural network as high-dimensional features to simplify what inversion model should learn. The core idea of our scheme is to reuse some parameters of the local pretraining model. Extensive experiments have verified the effectiveness of our method in convolutional neural networks on LFW, pubFig, MNIST data sets. Experimental results show that even with a few queries, our inversion method still work accurately and is superior to other technologies. It is worth mentioning that our method makes it more difficult for administrators to defend against the attack and elicit more investigations for privacy-preserving.
Kanghua Mo, Xiaozhang Liu, Teng Huang 0001, Anli Yan
Int. J. Intell. Syst.4