arXiv:2409.17767cs.CRcs.AI2024-09被引 16

利用图像批次空间相关性,提升联邦学习梯度反演攻击效果

Federated Learning under Attack: Improving Gradient Inversion for Batch of Images

  • 引入反馈混合机制,利用图像批次的空间关联性优化梯度反演
  • 攻击成功率提升19.18%,每张图像迭代次数减少48.82%
  • 对隐私安全研究者有重要参考价值,适用于评估联邦学习漏洞

联邦学习(FL)是一种能够保护用户数据隐私的机器学习方法。在该方法中,客户端在本地数据集上训练模型,中央服务器聚合来自各客户端的学习参数,从而训练全局模型,而无需共享用户数据。然而,现有研究表明,针对FL系统存在多种攻击手段。例如,梯度反演或泄露攻击可高精度还原联邦学习训练阶段使用的本地数据。本文提出一种名为深度梯度泄漏反馈混合(DLG-FB)的方法,通过考虑图像批次中普遍存在的空间相关性,改进梯度反演攻击。实验结果表明,该方法在攻击成功率上提升了19.18%,同时每张图像所需的迭代次数减少了48.82%。

原文摘要 · Abstract (English)

Federated Learning (FL) has emerged as a machine learning approach able to preserve the privacy of user's data. Applying FL, clients train machine learning models on a local dataset and a central server aggregates the learned parameters coming from the clients, training a global machine learning model without sharing user's data. However, the state-of-the-art shows several approaches to promote attacks on FL systems. For instance, inverting or leaking gradient attacks can find, with high precision, the local dataset used during the training phase of the FL. This paper presents an approach, called Deep Leakage from Gradients with Feedback Blending (DLG-FB), which is able to improve the inverting gradient attack, considering the spatial correlation that typically exists in batches of images. The performed evaluation shows an improvement of 19.18% and 48,82% in terms of attack success rate and the number of iterations per attacked image, respectively.

联邦学习梯度反演隐私攻击图像重建

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。