Active Membership Inference Attack under Local Differential Privacy in Federated Learning

Active Membership Inference Attack under Local Differential Privacy in Federated Learning
复制标题

DOI:
10.48550/arxiv.2302.12685
复制
发表时间:
2023-02
期刊:
ArXiv
影响因子:
--
通讯作者:
Truc D. T. Nguyen;Phung Lai;K. Tran;Nhathai Phan;M. Thai
Truc D. T. Nguyen;Phung Lai;K. Tran;Nhathai Phan;M. Thai
中科院分区:
其他
文献类型:
--
作者:
Truc D. T. Nguyen;Phung Lai;K. Tran;Nhathai Phan;M. Thai

文献摘要

被引文献

相似文献

联邦学习(FL)最初被认为是一种通过协调服务器进行数据隐私保护的客户端协作学习框架。在本文中,我们提出了一种新的主动成员推理(AMI)攻击进行了一个不诚实的服务器在FL。在AMI攻击中,服务器工艺和嵌入恶意参数到全局模型,以有效地推断目标数据样本是否包括在客户端的私人训练数据或没有。通过非线性决策边界利用数据特征之间的相关性,具有认证成功保证的AMI攻击可以在严格的本地差分隐私(LDP)保护下实现极高的成功率,从而将客户端的训练数据暴露于显著的隐私风险中。在几个基准数据集上的理论和实验结果表明,添加足够的隐私保护噪声来防止我们的攻击会显着损害FL的模型效用。
Federated learning (FL) was originally regarded as a framework for collaborative learning among clients with data privacy protection through a coordinating server. In this paper, we propose a new active membership inference (AMI) attack carried out by a dishonest server in FL. In AMI attacks, the server crafts and embeds malicious parameters into global models to effectively infer whether a target data sample is included in a client's private training data or not. By exploiting the correlation among data features through a non-linear decision boundary, AMI attacks with a certified guarantee of success can achieve severely high success rates under rigorous local differential privacy (LDP) protection; thereby exposing clients' training data to significant privacy risk. Theoretical and experimental results on several benchmark datasets show that adding sufficient privacy-preserving noise to prevent our attack would significantly damage FL's model utility.