scieee AI-readable full text Open interactive document viewer

Membership Inference Attacks Against Time-Series Models

Koren, Noam; Goldsteen, Abigail; Amit, Guy; Farkash, Ariel

Full text

Proceedings of Machine Learning Research 260:-, 2024 ACML 2024 Membership Inference Attacks Against Time-Series Models Noam Koren noam.k[email protected] Abigail Goldsteen abigail[email protected] Guy Amit [email protected] Ariel Farkash [email protected] IBM Research, Haifa, Israel Editors: Vu Nguyen and Hsuan-Tien Lin Abstract Analyzing time-series data that contains personal information, particularly in the medical field, presents serious privacy concerns. Sensitive health data from patients is often used to train machine learning models for diagnostics and ongoing care. Assessing the privacy risk of such models is crucial to making knowledgeable decisions on whether to use a model in production or share it with third parties. Membership Inference Attacks (MIA) are a key method for this kind of evaluation, however time-series prediction models have not been thoroughly studied in this context. We explore existing MIA techniques on time-series models, and introduce new features, focusing on the seasonality and trend components of the data. Seasonality is estimated using a multivariate Fourier transform, and a low-degree polynomial is used to approximate trends. We applied these techniques to various types of time-series models, using datasets from the health domain. Our results demonstrate that these new features enhance the effectiveness of MIAs in identifying membership, improving the understanding of privacy risks in medical data applications. Keywords: Privacy, Machine Learning, Time-Series, Membership Inference 1. Introduction There is a clear conflict between the ever-increasing interest in analyzing personal data to enhance and improve processes, and the need to preserve the privacy of data subjects. In the medical domain, sensitive data from patients is often used to train machine learning (ML) models that aid physicians in diagnostics and treatment. ML models are also utilized within medical devices and applications to predict malfunctions and improve ongoing care. Assessing the privacy risk of such models is crucial to enable making knowledgeable decisions on whether to use a model in production, share it with third parties, or deploy it in patients’ homes. Privacy risk assessment is often achieved by running membership inference attacks against the models and measuring their success rate. Membership inference attacks (MIA) attempt to distinguish between samples that were part of a target model’s training data (called members) and samples that were not (nonmembers), based on the model’s outputs. Many such attacks are based on training a binary classifier as an attack model Shokri et al. (2016). These attacks can be applied to various model types, including classification Shokri et al. (2016), regression Truex et al. (2019), graph He et al. (2021), and generative Hayes et al. (2017) models. However, MIA against time-series prediction models, has not yet been properly researched. ©2024 N. Koren, A. Goldsteen, G. Amit & A. Farkash. arXiv:2407.02870v2 [cs.LG] 22 Sep 2024 Koren Goldsteen Amit Farkash This paper addresses this gap by evaluating existing membership inference approaches on time-series forecasting models and introducing new features specifically designed for these models. Our main contribution is the addition of two novel features that exploit the trend and seasonality components of time-series data. The trend is approximated by fitting a low-degree polynomial and the seasonality is estimated using the Discrete Fourier Transform (DFT). Since time series fundamentally consist of trend and seasonality components, it is reasonable to assume that time-series models are more adept at accurately estimating these elements in series encountered during training. Additionally, various state-of-the-art forecasting models, such as Neural Fourier Transform (NFT) Koren and Radinsky (2024), TimesNet Wu et al. (2023), etc., specifically incorporate those components into their design. Consequently, when targeting a time-series prediction model, there is a significant likelihood that the model will precisely estimate the series’ seasonality and trend of its training data, providing a strategic advantage in MIAs. This underscores the importance of considering these features when assessing the vulnerability of time-series models. The impact of adding seasonality and trend as input features to MIA models is empirically evaluated by testing different combinations of existing and new features. The evaluation is performed on six time-series prediction models, using two medical datasets. The results demonstrate significant improvements across multiple prediction horizons, ranging from 3% to 26%, confirming the efficacy of the proposed attack features. This is an important first step towards proper privacy assessment methods for time-series models, which have so far been mostly overlooked. 2. Background 2.1. Time-Series Forecasting models Time series forecasting has evolved significantly, initially relying on linear models like ARIMA Zhang (2003) and Exponential Smoothing Gardner Jr (1985). However, with deep learning advancements, neural network architectures such as LSTM Yu et al. (2019) and GRU Dey and Salem (2017) showed superior performance over traditional methods. Recently, Convolutional Neural Networks (CNNs) Alzubaidi et al. (2021) and Temporal Convolutional Networks (TCNs) Hewage et al. (2020) have demonstrated state-of-the-art results. The Transformer architecture Wen et al. (2022) was also adapted for forecasting, with models like AutoFormer Wu et al. (2021) and FEDformer Zhou et al. (2022) as leading architectures. However, Zeng et al. (2022) proposed DLinear, a simple linear model, challenging the efficacy of transformers. The subsequent models TimesNet Wu et al. (2023), and PatchTST Nie et al. (2022) improved upon DLinear, while the NFT model Koren and Radinsky (2024) emerged as a top-performing multivariate time-series model. Multidimensional Fourier Transform. The Fourier Transform has been widely used in time series analysis to identify periodic patterns or cycles in the data Yi et al. (2023). By converting time-series data into the frequency domain, one can identify the main frequencies at which these cycles occur Nussbaumer (1982). Several forecasting models use Fourier Transforms for better performance. Autoformer employs Fast Fourier Transform for autocorrelation Wu et al. (2021), FEDformer focuses on key frequencies Zhou et al. (2022), and the Fourier Neural Operator approximates partial 2 MIAs on Time-Series Models differential equations operators with Fourier Transforms Li et al. (2020). TimesNet uses Fourier Transforms for feature decomposition to capture periodic patterns Wu et al. (2023). The Multidimensional Fourier Transform (MFT) Tolimieri et al. (2012) extends the traditional Fourier Transform to handle multi-dimensional data. We drew inspiration from the Neural Fourier Transform (NFT) Koren and Radinsky (2024), and used a 2-dimensional Discrete Fourier Transform (DFT) to extract the seasonality of the time series. 2.2. Membership Inference Attacks Membership inference attacks (MIAs) represent a significant privacy threat in machine learning. In these attacks, an adversary aims to determine whether a specific data record, x, was included in the training set of a model, D. If successful, the attack can reveal sensitive information about individuals, such as their medical history, financial status, or personal preferences. Moreover, MIAs can also be used to identify individuals who are part of a specific group or community, potentially leading to discrimination, or physical harm. Formally, given access to a machine learning model M, the attacker seeks to ascertain the membership of a data sample xin D, i.e; to check if x∈D. To this end the attacker typically analyzes M’s outputs, and produces numeric characteristics (features), that will enable it to distinguish members of the training data from none members. Such features may include M’s loss Shokri et al. (2016) on the sample, the log-probabilities Carlini et al. (2022b) and entropy of the outputs. In the context of time-series forecasting models, a malicious attacker seeks to determine whether a specific time series was utilized in the model’s training dataset, such as a patient’s ECG test results. This type of attack poses a significant threat in industries like healthcare and finance, where sensitive time-series data is frequently leveraged to develop predictive models, and the unauthorized disclosure of such information could have severe consequences. 3. Related work In the realm of time series, Hisamoto et al. studied membership inference on sequenceto-sequence (seq2seq) models in the context of machine translation, where the output is a chained sequence of classifications Hisamoto et al. (2020). This differs from medical sequence modeling whose input features and outputs are numerical and continuous. Pyrgelis et al. Pyrgelis et al. (2017) presented the first study on the feasibility of MIAs on aggregate location time series, modeling the problem as a classification task to distinguish whether a target user is part of an aggregate. Their empirical evaluation on mobility datasets shows that MIAs are a privacy threat, influenced by the adversary’s prior knowledge, data characteristics, number of users, and aggregation timeframe. Similarly, Voyez et al. Voyez et al. (2022) explored the vulnerability of aggregated timeseries data to MIAs, introducing a linear programming-based attack that leverages the correlation between the length of the published time series and the size of the aggregated data. Their experiments demonstrate that aggregated time series data can be highly susceptible to privacy breaches, emphasizing the need for better privacy-preserving techniques, particularly in the medical domain. However, to our knowledge, risk assessment in general and MIA specifically has not been thoroughly explored on ML models trained on numerical time-series data. This presented 3 Koren Goldsteen Amit Farkash us with an opportunity for novel applications and advancements in attacking time-series models, potentially unlocking new insights and methodologies in this area. 4. Methodology 4.1. Problem Statement This study focuses on MIA on multivariate time-series forecasting models. We assume that the attacker can access a complete sample that was either used in model training or not. In time-series data, training samples consist of data points up to time T(lookback), denoted as y= [y1, . . . , yT]∈RM×T, and the model predicts Hdata points onward (horizon), denoted as Y= [yT+1, . . . , yT+H]∈RM×H, where yt∈RMfor t= 1, . . . , T +H, and Mis the number of variables. To simplify, we consider a lookback window of length t≤T, ending at the most recent observation yT. This window serves as the input (sample) to the model and is denoted X∈RM×t= [yT−t+1, . . . , yT]. The forecast of Yis represented as ˆ Y. Our task is to determine if a specific sample, X, is part of the training data, D, i.e; X∈Dby comparing the real future values, Y, and the models predicted values, ˆ Y. 4.2. Features for MIA In the context of MIA, the attack features are the set of attributes or characteristics that the attack model leverages to determine whether a given data sample was a part of the training set (member) or not (non-member). As in any ML model, selecting the correct attack features is critical, as they form the basis upon which the attack model makes its predictions. An optimal set of attack features can significantly improve the success of the attack, potentially posing a much higher privacy risk. Our goal is to find attack features that will yield good MIA results for time-series models. This involves leveraging the characteristics of time-series data by identifying features that capture its unique aspects. Hence, the introduced features isolate the seasonality and trend components of the model’s prediction, contrasted with those of the true data. Figure 1 illustrates this process from the initial forecasting model to the final attack setup. Figure 1: Flowchart illustrating the process from the initial forecasting model to the final attack model, highlighting how extracted features are used for MIAs. Given that time-series data inherently includes components such as trend and seasonality, models trained on such data are particularly good at capturing those elements. This proficiency is leveraged by a variety of forecasting models, including Neural Fourier Transform (NFT) Koren and Radinsky (2024), TimesNet Wu et al. (2023), Fedformer Zhou et al. (2022), Autoformer Wu et al. (2021), Fourier Neural Operator (FNO) Li et al. (2020), NBEATS Oreshkin et al. (2019), NeuralProphet Triebe et al. (2021), ARIMA Zhang (2003), 4 MIAs on Time-Series Models etc., all of which explicitly integrate these elements into their predictions. Thus, when attacking a time-series prediction model, we aim to take advantage of the model’s ability to accurately predict the series’ trend and seasonality, thus offering a tactical advantage in MIAs. This highlights the critical need to consider these characteristics when evaluating the susceptibility of time-series models to such privacy threats. In this work, to effectively capture the seasonality, we employ the Multidimensional Fourier Transform, which excels in extracting periodic patterns from time-series data Musbah and El-Hawary (2019). We identify the predominant trend through a low-degree polynomial fit, allowing us to find the principal direction while filtering variations Masry (1996). 4.2.1. Seasonality We detect seasonality in multivariate temporal data with the 2-dimensional Discrete Fourier Transform (2D-DFT) as done in Koren and Radinsky (2024). This method breaks down the dataset into its frequency components, considering both the range of variables and the timeline. This approach is essential for datasets where the interaction between different variables can create new seasonality patterns that are not seen in the univariate context. The 2D-DFT is applied to the matrix Y∈RM×H, where Mis the number of variables, and His the number of predicted time points. This process involves two sequential 1DDFTs. First, a column-wise 1D-DFT is applied to Yusing the Fourier matrix FM, which captures transformations across the variables. Next, a row-wise 1D-DFT is performed using the Fourier matrix FH, which encodes the temporal structure of the data. The 2D-DFT can be compactly represented as: C=FMYFH ⊤(1) Here, the matrix Ccontains the Fourier coefficients. Following are the Fourier matrices FMand FHthat achieve the desired Fourier transformation: FM=         cos(2π·0·0 M)·· cos(2π·0·M−1 M) . .. .. . cos(2π·M 2·0 M)·· cos(2π·M 2·M−1 M) sin(2π·0·0 M)·· sin(2π·0·M−1 M) . .. .. . sin(2π·M 2·0 M)·· sin(2π·M 2·M−1 M)         FH=         cos(2π·0·0 H)·· cos(2π·0·H−1 H) . .. .. . cos(2π·H 2·0 H)·· cos(2π·H 2·H−1 H) sin(2π·0·0 H)·· sin(2π·0·H−1 H) . .. .. . sin(2π·H 2·0 H)·· sin(2π·H 2·H−1 H)         The input features to the attack derived from this method are: 1. Coefficients of the Fourier series corresponding to the true values: C=F1 ⊤×Y×F2 5 Koren Goldsteen Amit Farkash 2. Coefficients of the Fourier series corresponding to the model’s predicted values: ˆ C=F1 ⊤׈ Y×F2 3. The L2norm between the coefficients of the true and predicted values: ||C−ˆ C||2 4.2.2. Trend Consider a multivariate time series Ywith Htime points and Mvariables. Each variable’s series is approximated using a polynomial of degree d. This approximation can be represented as: Y=P×A(2) where Ais the coefficients matrix, and Pis the Vandermonde matrix, constructed from the time vector t=[0,1,...,H−1] H.Pcontains powers of tup to d−1, has dimensions d×Hand is defined as: P=        1 1 · · · 1 t1t2· · · tH t2 1t2 2· · · t2 H . . .. . ..... . . td−1 1td−1 2· · · td−1 H        where ti=i−1 Hfor i= 1,2, . . . , H. The coefficients matrix Ais obtained by the least squares solution: A= (PTP)−1PTY The input features to the attack derived from this method are: 1. Coefficients of the polynomial outlining the trend of the true values: A= (PTP)−1PTY 2. Coefficients of the polynomial outlining the trend of the model’s predicted values: ˆ A= (PTP)−1PTˆ Y 3. The L2norm between the coefficients of the true and predicted values: ||A−ˆ A||2 4.2.3. Mean Absolute Scaled Error and Mean Squared Error Additionally, this study investigates incorporating the Mean Absolute Scaled Error (MASE), a scaled measure for assessing forecast accuracy by comparing the mean absolute error of a model against a na¨ıve baseline forecast, as outlined by Hyndman and Koehler (2006), and the Mean Squared Error (MSE), Das et al. (2004), metrics as features for the attack model. MASE = 1 HPH i=1 |yT+i−ˆyT+i| 1 H−1PH i=2 |yT+i−yT+i−1| 6 MIAs on Time-Series Models MSE = 1 H H X i=1 (yT+i−ˆyT+i)2 These metrics are extended to the multivariate case by averaging the respective univariate values across all variables. 5. Experimental Setup 5.1. Threat Model and MIA Attack Setup Following previous privacy assessment studies Shachor et al. (2023); Amit et al. (2024); Anderson et al. (2024), we adopt a gray-box threat model, assuming the attacker has access to both a subset of the model’s training data and a set of non-training samples. The access to this data, allows estimating a worst case privacy risk for a model before deployment, without the need of developing shadow models Shokri et al. (2016). To execute the attack, we leverage the privacy risk assessment framework from Shachor et al. (2023), which builds upon recent breakthroughs in MIAs Carlini et al. (2022a); Shokri et al. (2016). This framework leverages the ensemble approach, creating many specialized attack models for different subsets of the data. The framework harnesses a diverse set of input features extracted from the target model’s inputs and outputs. Through an exhaustive grid search, it systematically explores various attack model architectures, hyperparameters, and preprocessing techniques to identify the optimal configuration that yields maximum attack performance. The attack models trained by the risk assessment framework utilize various combinations of the following features: (1) Seasonality denoted as, S, (2) Trend denoted as, T(with a polynomial degree of 4 like done in Koren and Radinsky (2024); Oreshkin et al. (2019)), (3) MASE , (4) MSE , and (5) Predicted Values denoted as, PV . In this evaluation, we applied the framework to conduct five attack instances, each with three runs. An instance refers to executing the entire attack optimization process on a different random data sample, while the runs involve different splits of the data sample to fit and infer the attack model within each instance. For each instance, a sample of 450 members and 450 non-members was chosen at random. Results were averaged across all runs and instances to ensure robustness. 5.2. Datasets In this evaluation, two multivariate time-series medical datasets were used: •EEG: 36-lead EEG database, which contains more than 1000 EEG recordings dating from 2002 to the present, sampled at a frequency of 250 Hz Obeid and Picone (2016). Our subset includes data from 32 patients, and the first 3-leads for each patient. •ECG: Georgia 12-Lead ECG Challenge Database, curated by Emory University Goldberger et al. (2000). The complete database contains ECG recordings of over 10,000 individuals, sampled at a frequency of 500 Hz, and collected from various healthcare settings worldwide. Our subset features ECG time-series data from 600 individuals. 7 Koren Goldsteen Amit Farkash Data preprocessing included outlier removal using the Interquartile Range method, imputation of missing values via mean substitution, and data standardization. For both datasets, The data was partitioned into three distinct subsets: 42.5% of the patients were used for training the model, 15% for validation, and the remaining 42.5% were reserved as non-member data points for the attack model. The validation set was used to tune the models parameters, thus creating strong models to attack. The non-member data points remained uninvolved in training or validating the models but were used in subsequent attack experiments. Additionally, the data was split into lookbacks and horizons using the sliding window approach. Statistics on the datasets can be found in Table 1. Table 1: Datasets Statistics Dataset Num of Variables Timesteps Lookback Prediction Horizons EEG 3 9620519 100 1, 5, 10, 15, 20 ECG 12 2393563 100 1, 5, 10, 15, 20, 25, 30 5.3. Models We performed attacks against various state-of-the-art time-series forecasting architectures: •DLinear: Featured a dimension of 16 and a dropout rate of 0.1 Zeng et al. (2022). •Temporal Convolutional Network (TCN): Configured with channels set to [2, 2], a kernel size of 2, and a dropout rate of 0.2 Hewage et al. (2020). •Long Short Term Memory (LSTM): Featured a 2-layer structure with hidden dimensions set to 50 Yu et al. (2019). •Neural Fourier Transform (NFT): Configured with Fourier granularity of 8 for the seasonality blocks and a polynomial degree of 4 for the trend blocks, comprising 2 blocks per stack Koren and Radinsky (2024). •TimesNet: Model dimension was set to 16 and a dropout rate of 0.1 Wu et al. (2023). •PatchTST: This transformer model included one encoder and decoder layer, a model dimension of 16, and a dropout rate of 0.1 Nie et al. (2022). The parameters for each model were chosen based on their performance on a validation set, ensuring optimal configuration for our analysis. In Table 3, the number of parameters for each model is detailed. For all models, the MSE loss was utilized during model training. Figure 2presents the performance (MSE) of each model on the test set (non-members) for different prediction horizons. 6. Results To assess the robustness of the proposed features for MIAs on time-series models we compare them to baseline attacks, selected from standard gray-box approaches. In grey-box, where 8 MIAs on Time-Series Models 0 10 20 5·10−2 0.1 Horizon MSE EEG 0 10 20 30 0 0.2 0.4 Horizon MSE ECG NFT TimesNet PatchTST DLinear TCN LSTM Figure 2: MSE values of models with varying horizons on ECG and EEG datasets the attacker has to both a subset of the model’s training data and a set of non-training samples, typical attacks are based on loss or predictions, similar to those in black-box mode since in both the attacker relies on loss or prediction information Gupta et al. (2021). In all experiments, four baselines were employed: loss-based attacks using MSE, MASE, and a combination of both, as well as attacks based on predicted values. The results were evaluated using two key metrics: Area Under the Receiver Operating Characteristic curve (AUC-ROC) and True Positive Rate (TPR) at a fixed False Positive Rate (FPR) of 1%. 6.1. Area Under the ROC Curve Results 6.1.1. Performance Against Loss Based Attacks Figures 3and 4highlight the strong performance of the Seasonality (S) and Trend (T) features across various time-series models and datasets. The highest AUC-ROC values were achieved with feature combinations that included the Trend or Seasonality features, outperforming the baseline attacks. For the EEG dataset, when looking at the different models, the improvement percentage of the best-performing feature combination compared to the MSE-only attack, averaged across horizons, ranged from 8.44% (with average std 0.007) to 26.41% (with average std 0.006). For the ECG dataset, improvements ranged from 2.97% (with average std 0.008) to 24.55% (with averaged std 0.007). The TimesNet model showed the best improvements in both datasets. The MASE feature achieved the lowest attack performance, however, the combination of MASE and MSE generally surpassed attacks that use the MSE feature alone. Overall, the results indicate that the Seasonality and Trend features provide a robust solution for membership inference attacks for time-series forecasting models. Its consistent performance across different models, datasets, and horizons highlights its effectiveness. Analysis of Attack Performance by Prediction Horizon. We analyzed the relative attack AUC-ROC as a function of the prediction horizon. To this end, we computed, for each dataset, the correlation between the prediction horizon (previously denoted by H) and the improvement percentage (MSE-only attack relative to the highest attack value). See Table 2for the resulting correlations. We consistently observed a positive correlation for all the models except for NFT and TCN on the ECG dataset. We assume that the negative correlation can be traced back to the difference in architecture. Notably, the NFT and TCN models both are based on convolutional layers, which capture the trend and seasonality in 9 Koren Goldsteen Amit Farkash Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. Membership inference attacks against machine learning models (s&p’17). 2016. Richard Tolimieri, Myoung An, and Chao Lu. Mathematics of multidimensional Fourier transform algorithms. Springer Science & Business Media, 2012. Oskar Triebe, Hansika Hewamalage, Polina Pilyugina, Nikolay Laptev, Christoph Bergmeir, and Ram Rajagopal. Neuralprophet: Explainable forecasting at scale. arXiv preprint arXiv:2111.15397, 2021. Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Lei Yu, and Wenqi Wei. Demystifying membership inference attacks in machine learning as a service. IEEE transactions on services computing, 14(6):2073–2089, 2019. Antonin Voyez, Tristan Allard, Gildas Avoine, Pierre Cauchois, Elisa Fromont, and Matthieu Simonin. Membership inference attacks on aggregated time series with linear programming. In SECRYPT 2022 - 19th International Conference on Security and Cryptography, pages 193–204. Springer, 2022. Qingsong Wen, Tian Zhou, Chaoli Zhang, Weiqi Chen, Ziqing Ma, Junchi Yan, and Liang Sun. Transformers in time series: A survey. arXiv preprint arXiv:2202.07125, 2022. Haixu Wu, Jiehui Xu, Jianmin Wang, and Mingsheng Long. Autoformer: Decomposition transformers with auto-correlation for long-term series forecasting. Advances in neural information processing systems, 34:22419–22430, 2021. Haixu Wu, Tengge Hu, Yong Liu, Hang Zhou, Jianmin Wang, and Mingsheng Long. Timesnet: Temporal 2d-variation modeling for general time series analysis. In The eleventh international conference on learning representations, 2023. Kun Yi, Qi Zhang, Longbing Cao, Shoujin Wang, Guodong Long, Liang Hu, Hui He, Zhendong Niu, Wei Fan, and Hui Xiong. A survey on deep learning based time series analysis with frequency transformation. arXiv preprint arXiv:2302.02173, 2023. Yong Yu, Xiaosheng Si, Changhua Hu, and Jianxun Zhang. A review of recurrent neural networks: Lstm cells and network architectures. Neural computation, 31(7):1235–1270, 2019. Ailing Zeng, Muxi Chen, Lei Zhang, and Qiang Xu. Are transformers effective for time series forecasting? In Proceedings of the AAAI conference on artificial intelligence, volume 37, pages 11121–11128, 2022. G Peter Zhang. Time series forecasting using a hybrid arima and neural network model. Neurocomputing, 50:159–175, 2003. Tian Zhou, Ziqing Ma, Qingsong Wen, Xue Wang, Liang Sun, and Rong Jin. Fedformer: Frequency enhanced decomposed transformer for long-term series forecasting. In International conference on machine learning, pages 27268–27286. PMLR, 2022. 16