arXiv:2409.13875cs.LGcs.CR2024-09

工业联邦学习中,模型可泄露竞争对手的数据变化,存在隐蔽隐私风险。

Data Distribution Shifts in (Industrial) Federated Learning as a Privacy Issue

  • 通过分析共享模型内部状态检测数据分布微小变化
  • 攻击者能提前发现对手生产变化,即使不影响训练收敛
  • 适合关注工业级联邦学习隐私安全的研究者

我们研究工业联邦学习场景,即少数强大且可能竞争的工业方在第三方协调下合作,旨在提升服务。此类架构隐含潜在隐私风险,不同于跨设备设置。企业对知识产权和生产流程高度保密,其生产变化及时间点需严格保护。本文探讨一种情形:某合作者通过检测其他方潜在细微的时间性数据分布偏移,推断其生产变动。在此框架下,分布偏移本身即构成问题,无论是否影响训练收敛。因此,目标是寻找比传统评估指标更优的分布偏移检测方法。基于假设:即使微小偏移也会反映在协同学习的模型中,攻击者利用文献中的若干度量指标追踪共享模型内部状态,以捕捉关键变化。在基准数据集上的实证研究表明,一个诚实但好奇的攻击者能够检测到其他客户端的细微分布偏移,某些情况下远早于传统评估指标显现。

原文摘要 · Abstract (English)

We consider industrial federated learning, a collaboration between a small number of powerful, potentially competing industrial players, mediated by a third party aspiring to improve the service it provides to its customers. We argue that this configuration harbours covert privacy risks that do not arise in e.g. cross-device settings. Companies are very protective of their intellectual property and production processes. Information about changes to their production and the timing of which is to be kept private. We study a scenario in which one of the collaborators infers changes to their competitors' production by detecting potentially subtle temporal data distribution shifts. In this framing, a data distribution shift is always problematic, even if it has no negative effect on training convergence. Thus, our goal is to find means that allow the detection of distributional shifts better than customary evaluation metrics. Based on the assumption that even minor shifts translate into the collaboratively learned machine learning model, the attacker tracks the shared models' internal state with a selection of metrics from literature in order to pick up on relevant changes. In an empirical study on benchmark datasets, we show an honest-but-curious attacker to be capable of detecting subtle distributional shifts on other clients, in some cases long before they become obvious in evaluation.

联邦学习隐私安全数据偏移工业应用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。