A Novel Attribute Reconstruction Attack in Federated Learning

A Novel Attribute Reconstruction Attack in Federated Learning
复制标题

DOI:
--
复制
发表时间:
2021-08
期刊:
ArXiv
影响因子:
--
通讯作者:
L. Lyu;Chen Chen-Chen
L. Lyu;Chen Chen-Chen
中科院分区:
其他
文献类型:
--
作者:
L. Lyu;Chen Chen-Chen

文献摘要

被引文献

相似文献

联邦学习(FL)作为一种有前途的学习范式出现,使众多参与者能够在不暴露其私人训练数据的情况下构建联合ML模型。现有的FL设计已被证明存在漏洞,这些漏洞可以被系统内外的对手利用,从而损害数据隐私。然而,大多数当前的作品通过利用小批量数据上的梯度来进行攻击,这在FL中不太实用。在这项工作中,我们考虑了一个更实用和有趣的场景,其中参与者共享他们的epoch平均梯度(在至少1个epoch的本地训练后共享梯度),而不是像以前的作品那样每个示例或小批量平均梯度。我们执行的属性重构攻击(ARA)的恶意服务器在FL系统中发起的第一个系统的评估,并实证证明,共享的历元平均局部模型梯度可以揭示任何受害者参与者的本地训练数据的敏感属性。为了实现这一目标,我们开发了一种更有效和高效的梯度匹配的方法称为余弦匹配重建训练数据属性。我们评估我们对各种真实世界数据集,场景,假设的攻击。实验结果表明,该方法的属性攻击性能优于大多数已有的基线算法.
Federated learning (FL) emerged as a promising learning paradigm to enable a multitude of participants to construct a joint ML model without exposing their private training data. Existing FL designs have been shown to exhibit vulnerabilities which can be exploited by adversaries both within and outside of the system to compromise data privacy. However, most current works conduct attacks by leveraging gradients on a small batch of data, which is less practical in FL. In this work, we consider a more practical and interesting scenario in which participants share their epoch-averaged gradients (share gradients after at least 1 epoch of local training) rather than per-example or small batch-averaged gradients as in previous works. We perform the first systematic evaluation of attribute reconstruction attack (ARA) launched by the malicious server in the FL system, and empirically demonstrate that the shared epoch-averaged local model gradients can reveal sensitive attributes of local training data of any victim participant. To achieve this goal, we develop a more effective and efficient gradient matching based method called cos-matching to reconstruct the training data attributes. We evaluate our attacks on a variety of real-world datasets, scenarios, assumptions. Our experiments show that our proposed method achieves better attribute attack performance than most existing baselines.