View Item 
        •   Utrecht University Student Theses Repository Home
        • UU Theses Repository
        • Theses
        • View Item
        •   Utrecht University Student Theses Repository Home
        • UU Theses Repository
        • Theses
        • View Item
        JavaScript is disabled for your browser. Some features of this site may not work without it.

        Browse

        All of UU Student Theses RepositoryBy Issue DateAuthorsTitlesSubjectsThis CollectionBy Issue DateAuthorsTitlesSubjects

        White-box passive attacks and robust model learning defenses on image classification models

        Thumbnail
        View/Open
        LitRev (14).pdf (13.32Mb)
        Publication date
        2025
        Author
        Blom, Frederieke
        Metadata
        Show full item record
        Summary
        Federated learning allows multiple parties to collaboratively train a model without sharing sensitive data, making it suitable for applications such as border control, criminal investigation, and device security. However, models trained in this way remain vulnerable to privacy attacks. Two notable threats are membership inference attacks (MIAs), which aim to determine whether specific samples were included in the training data, and model inversion (MI) attacks, which attempt to reconstruct training samples from the model. State-of-the-art defenses for MI include transfer learning (TL) and bidirectional dependency optimization (BiDO). For MIA, random cropping (RC) has shown a strong mitigation potential. This study investigates whether RC can be applied to a model typically used to demonstrate MI attacks (without deteriorating this models test accuracy), and how effective the combination of the three defenses is against a strong MIA attack. Each defense is applied individually, in pairs, and in full combination, with parameters fine-tuned accordingly. The models are then subjected to two state-of-the-art attacks: IF-GMI as MI attack on undefended models, and LiRA as MIA attack on defended and undefended models. Each defense configuration demonstrates a reduction in data leakage, with acceptable utility and cost. The results show that the combination of multiple defenses (TL + BiDO + RC) achieves the greatest mitigation effect against MIA, without notable degradation in performance.
        URI
        https://studenttheses.uu.nl/handle/20.500.12932/49895
        Collections
        • Theses

        Related items

        Showing items related by title, author, creator and subject.

        • Modeling dual-task performance: do individualized models predict dual-task performance better than average models? 

          Cao, W. (2017)
          Understanding multitasking can be a complicated venture. The goal of this paper is to see whether using individual parameters for modeling dual-task will lead to better predictions of individual performance compared to ...
        • Modelling Wastewater Quantity and Quality in Mexico -- using an agent-based model 

          Chen, Y. (2021)
          Wastewater is a key element in regional and global water circles, and the discharge of a large quantity of untreated wastewater is posing serious threats to the environment and public health in Mexico. To have a thorough ...
        • Modelling offshore wind in the IMAGE/TIMER model 

          Gernaat, D.E.H.J. (2012)
          Current global energy consumption is expected to continue to grow as the global population is likely to increase towards 9 billion in 2050 while income levels per capita surge with 3-5% per year. Resource depletion, climate ...
        Utrecht university logo