Enhancing Trajectory Recovery From Gradients via Mobility Prior Knowledge

Enhancing Trajectory Recovery From Gradients via Mobility Prior Knowledge
复制标题

DOI:
10.1109/jiot.2022.3221964
复制
发表时间:
2023-03
影响因子:
10.6
通讯作者:
Kaiyue Zhang;Z. Fan;Xuan Song;Shui Yu
Kaiyue Zhang;Z. Fan;Xuan Song;Shui Yu
中科院分区:
计算机科学1区
文献类型:
--
作者:
Kaiyue Zhang;Z. Fan;Xuan Song;Shui Yu

文献摘要

相似文献

由于轨迹在智能交通系统中起着重要的作用,实现梯度下的轨迹恢复具有重要的应用价值。现有的研究表明,联邦学习容易受到从共享梯度中恢复原始训练数据的攻击。然而,我们发现利用轨迹数据进行梯度攻击很难成功。大多数现有的攻击在面对具有较高非线性和时间相关特征的模型(如目的地预测模型)时都具有最小的有效性。在本文中,我们提出了基于迁移率先验的梯度深度泄漏(DLGMP)算法来解决这些问题。提出的DLGMP算法利用时空结构信息作为先验迁移知识,大大缩小了初始搜索空间,降低了恢复难度。我们使用易于扩展的正则化项和Wasserstein GAN (WGAN)的对抗损失进一步改进了我们的算法,以帮助恢复准确合理的轨迹。在三个主流数据集上的实验证明了该算法的良好性能。我们还讨论了防止梯度攻击的几种可能的解决方案。
As trajectory plays an important role in intelligent transportation systems, achieving trajectory recovery from gradients is of great value. Existing research has shown that federated learning is vulnerable to attacks that recover the original training data from shared gradients. Still, we find that gradients attack is difficult to succeed with trajectory data. Most existing attacks have minimal effectiveness when facing models with higher nonlinearity and temporal-related characteristics, such as destination prediction models. In this article, we propose deep leakage from gradients with mobility prior (DLGMP) algorithm to solve these problems. The proposed DLGMP algorithm leverages the spatiotemporal structural information as the prior mobility knowledge, narrowing down the initial search space sharply and decreasing the difficulty of recovery. We further improve our algorithm with an easily extensible regularization term and an adversarial loss of Wasserstein GAN (WGAN) to help recover accurate and reasonable trajectories. Experiments on three mainstream data sets show good performance of our DLGMP algorithm. We also discuss several possible solutions to prevent gradients attack.