arXiv:2409.19301cs.CRcs.AI2024-09被引 6

实验证明联邦学习隐私攻击远比想象困难,现有方法在真实场景下均失效。

Privacy Attack in Federated Learning is Not Easy: An Experimental Study

  • 在真实联邦环境测试多种攻击方法,评估其实际效果。
  • 所有主流攻击算法在无防御情况下均无法有效恢复客户端数据。
  • 为研究者提供真实评估基准,警示过度乐观的隐私威胁判断。

联邦学习(FL)是一种新兴的分布式机器学习范式,旨在保护隐私。与传统集中式学习不同,FL允许多个用户在不共享原始数据的前提下协同训练全局模型,从而显著降低隐私泄露风险。然而,近期研究表明,FL无法完全保证隐私安全,攻击者可能通过通信的模型梯度提取用户私有数据。尽管已有大量隐私攻击算法被提出,但多数仅针对单步梯度重建私有数据。这些方法在真实联邦环境中的有效性仍不明确,是否存在其他限制也尚不清楚。本文旨在帮助研究者更准确地理解并评估联邦学习中的隐私攻击效果。我们分析了相关研究论文,并在真实联邦环境中开展实验,对比多种攻击方法的表现。实验结果表明,在无防御策略的真实联邦设置中,现有最先进的隐私攻击算法均无法有效突破客户端数据隐私,这表明联邦学习中的隐私攻击比预期更为困难。

原文摘要 · Abstract (English)

Federated learning (FL) is an emerging distributed machine learning paradigm proposed for privacy preservation. Unlike traditional centralized learning approaches, FL enables multiple users to collaboratively train a shared global model without disclosing their own data, thereby significantly reducing the potential risk of privacy leakage. However, recent studies have indicated that FL cannot entirely guarantee privacy protection, and attackers may still be able to extract users' private data through the communicated model gradients. Although numerous privacy attack FL algorithms have been developed, most are designed to reconstruct private data from a single step of calculated gradients. It remains uncertain whether these methods are effective in realistic federated environments or if they have other limitations. In this paper, we aim to help researchers better understand and evaluate the effectiveness of privacy attacks on FL. We analyze and discuss recent research papers on this topic and conduct experiments in a real FL environment to compare the performance of various attack methods. Our experimental results reveal that none of the existing state-of-the-art privacy attack algorithms can effectively breach private client data in realistic FL settings, even in the absence of defense strategies. This suggests that privacy attacks in FL are more challenging than initially anticipated.

联邦学习隐私攻击实验评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。