MSG: Stealing data from pruned neural networks via malicious sparsity guidance.

Shang, Jing; Wang, Jian; Wang, Kailun; Jiang, Nan; Liu, Jiqiang · Neural Netw · 2026

Where this comes from

Abstract

With the widespread adoption of machine learning cloud platforms, concerns over potential privacy risks in model training algorithms have grown. Attackers can exploit these platforms by deploying malicious algorithms to execute correlation value encoding attacks (CVEA). This attack mainly leverages the model's huge capacity for memorization, covertly embedding training data into the model's parameters. Once the model is published, attackers can extract these parameters and recover sensitive data. In this paper, we empirically demonstrate for the first time that common model pruning techniques significantly diminish the effectiveness and stealthiness of CVEA, as they reduce redundant parameters. We further propose a new pruning-resistant parameter encoding attack via Malicious Sparsity Guidance (MSG), which strategically embeds data into a selected subset of model parameters while actively guiding the pruning process. Specifically, MSG manipulates parameter importance during training to increase the likelihood that the parameters carrying embedded information are preserved after pruning. To further enhance stealthiness, we integrate knowledge transfer, allowing the encoded model to maintain high prediction accuracy before and after pruning. Comprehensive experiments across seven datasets and five model architectures demonstrate that MSG enables attackers to extract high-quality training data before and after model pruning. Moreover, knowledge transfer significantly narrows the accuracy gap between the pruned and unpruned encoded models, making the attack more inconspicuous.

Medical subject headings