A Comprehensive Study of Gradient Inversion Attacks in Federated Learning and Baseline Defense Strategies

A Comprehensive Study of Gradient Inversion Attacks in Federated Learning and Baseline Defense Strategies
复制标题

DOI:
10.1109/ciss56502.2023.10089719
复制
发表时间:
2023-03
期刊:
2023 57th Annual Conference on Information Sciences and Systems (CISS)
影响因子:
--
通讯作者:
Pretom Roy Ovi;A. Gangopadhyay
Pretom Roy Ovi;A. Gangopadhyay
中科院分区:
其他
文献类型:
--
作者:
Pretom Roy Ovi;A. Gangopadhyay

文献摘要

相似文献

随着对数据保密性和立法的更加重视,正在开发协作机器学习算法来保护敏感的私人数据。联邦学习(FL)是这些方法中最受欢迎的,并且FL使大量用户之间的协作模型构建成为可能,而不需要显式的数据共享。由于FL模型是通过梯度共享协议以分布式方式构建的,因此它们容易受到“梯度反转攻击”,其中敏感的训练数据是从原始梯度中提取的。重建数据的梯度反转攻击被认为是FL中最邪恶的隐私风险之一,因为攻击者秘密地监视梯度更新并从梯度中回溯以获得有关原始数据的信息,而不会影响模型训练质量。即使没有关于私有数据的先验知识,攻击者也可以通过中间梯度来破坏训练数据的机密性。现有的FL训练协议已被证明存在漏洞,可以被系统内外的对手利用,以损害数据隐私。因此,它是至关重要的,使FL系统设计人员意识到未来FL算法设计的隐私保护的影响。受此启发,我们的工作重点是探索FL中的数据机密性和完整性,其中我们强调了现有梯度反转攻击策略检索数据所使用的直觉,方法和基本假设。然后,我们研究了不同方法的局限性,并评估其在检索原始数据的定性性能。此外,我们评估了基线防御机制对这些攻击的有效性,以实现FL中强大的隐私保护。
With a greater emphasis on data confidentiality and legislation, collaborative machine learning algorithms are being developed to protect sensitive private data. Federated learning (FL) is the most popular of these methods, and FL enables collaborative model construction among a large number of users without the requirement for explicit data sharing. Because FL models are built in a distributed manner with gradient sharing protocol, they are vulnerable to “gradient inversion attacks,” where sensitive training data is extracted from raw gradients. Gradient inversion attacks to reconstruct data are regarded as one of the wickedest privacy risks in FL, as attackers covertly spy gradient updates and backtrack from the gradients to obtain information about the raw data without compromising model training quality. Even without prior knowledge about the private data, the attacker can breach the secrecy and confidentiality of the training data via the intermediate gradients. Existing FL training protocol have been proven to exhibit vulnerabilities that can be exploited by adversaries both within and outside the system to compromise data privacy. Thus, it is critical to make FL system designers aware of the implications of future FL algorithm design on privacy preservation. Motivated by this, our work focuses on exploring the data confidentiality and integrity in FL, where we emphasize the intuitions, approaches, and fundamental assumptions used by the existing strategies of gradient inversion attacks to retrieve the data. Then we examine the limitations of different approaches and evaluate their qualitative performance in retrieving raw data. Furthermore, we assessed the effectiveness of baseline defense mechanisms against these attacks for robust privacy preservation in FL.