Soteria: Provable Defense against Privacy Leakage in Federated Learning from Representation Perspective

Soteria: Provable Defense against Privacy Leakage in Federated Learning from Representation Perspective
复制标题

DOI:
10.1109/cvpr46437.2021.00919
复制
发表时间:
2020-12
期刊:
2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Jingwei Sun;Ang Li;Binghui Wang;Huanrui Yang;Hai Li;Yiran Chen
Jingwei Sun;Ang Li;Binghui Wang;Huanrui Yang;Hai Li;Yiran Chen
中科院分区:
其他
文献类型:
--
作者:
Jingwei Sun;Ang Li;Binghui Wang;Huanrui Yang;Hai Li;Yiran Chen

文献摘要

相似文献

联合学习(FL)是一种流行的分布式学习框架,它可以通过不显式共享私人数据来降低隐私风险。然而,最近的研究表明,共享模型更新会使FL容易受到推理攻击。在这项工作中,我们的主要观察结果是,来自梯度的数据表征泄露是外语隐私泄露的根本原因。我们还提供了对这一观察结果的分析,以解释数据演示是如何泄露的。在此基础上,针对FL中的模型反转攻击,提出了一种称为Soteria的防御方案。我们防御的关键思想是学习扰动数据表示,以便在保持FL性能的同时,重建数据的质量严重下降。此外,在应用我们的防御之后,我们还得到了对FL的证明的健壮性保证和对FedAvg的收敛保证。为了评估我们的防御,我们在MNIST和CIFAR10上进行了防御DLG攻击和GS攻击的实验。实验结果表明,在不牺牲精度的情况下,对于DLG攻击和GS攻击,本文提出的防御方法与基线防御方法相比,重建数据与原始数据之间的均方误差提高了160倍。因此,FL系统的私密性得到了显著提高。我们的代码可以在https://github.com/jeremy313/Soteria.上找到
Federated learning (FL) is a popular distributed learning framework that can reduce privacy risks by not explicitly sharing private data. However, recent works have demonstrated that sharing model updates makes FL vulnerable to inference attack. In this work, we show our key observation that the data representation leakage from gradients is the essential cause of privacy leakage in FL. We also provide an analysis of this observation to explain how the data presentation is leaked. Based on this observation, we propose a defense called Soteria against model inversion attack in FL. The key idea of our defense is learning to perturb data representation such that the quality of the reconstructed data is severely degraded, while FL performance is maintained. In addition, we derive a certified robustness guarantee to FL and a convergence guarantee to FedAvg, after applying our defense. To evaluate our defense, we conduct experiments on MNIST and CIFAR10 for defending against the DLG attack and GS attack. Without sacrificing accuracy, the results demonstrate that our proposed defense can increase the mean squared error between the reconstructed data and the raw data by as much as 160× for both DLG attack and GS attack, compared with baseline defense methods. Therefore, the privacy of the FL system is significantly improved. Our code can be found at https://github.com/jeremy313/Soteria.