Gradient Disaggregation: Breaking Privacy in Federated Learning by Reconstructing the User Participant Matrix

Gradient Disaggregation: Breaking Privacy in Federated Learning by Reconstructing the User Participant Matrix
复制标题

DOI:
--
复制
发表时间:
2021-06
期刊:
--
影响因子:
--
通讯作者:
Maximilian Lam;Gu-Yeon Wei;D. Brooks;V. Reddi;M. Mitzenmacher
Maximilian Lam;Gu-Yeon Wei;D. Brooks;V. Reddi;M. Mitzenmacher
中科院分区:
其他
文献类型:
--
作者:
Maximilian Lam;Gu-Yeon Wei;D. Brooks;V. Reddi;M. Mitzenmacher

文献摘要

被引文献

相似文献

我们证明了联邦学习中的聚合模型更新可能是不安全的。一个不受信任的中央服务器可能会从参与者之间的重复观察中分解用户更新,使服务器能够通过传统的梯度推理攻击恢复有关单个用户私人训练数据的特权信息。我们的方法围绕着通过利用通常用于监控、调试和管理联邦学习系统的设备分析的摘要信息,从聚合的模型更新中重构参与者信息(例如:用户参加了哪轮培训)。我们的攻击是并行的,我们成功地分解了多达数千参与者的设置上的用户更新。我们定量和定性地证明了对分解更新的各种推理攻击能力的显着改进。我们的攻击使学习属性归属于个体用户,违反了匿名性,并表明一个确定的中央服务器可能会破坏安全聚合协议,从而破坏联邦学习中个体用户的数据隐私。
We show that aggregated model updates in federated learning may be insecure. An untrusted central server may disaggregate user updates from sums of updates across participants given repeated observations, enabling the server to recover privileged information about individual users' private training data via traditional gradient inference attacks. Our method revolves around reconstructing participant information (e.g: which rounds of training users participated in) from aggregated model updates by leveraging summary information from device analytics commonly used to monitor, debug, and manage federated learning systems. Our attack is parallelizable and we successfully disaggregate user updates on settings with up to thousands of participants. We quantitatively and qualitatively demonstrate significant improvements in the capability of various inference attacks on the disaggregated updates. Our attack enables the attribution of learned properties to individual users, violating anonymity, and shows that a determined central server may undermine the secure aggregation protocol to break individual users' data privacy in federated learning.