arXiv:2409.19964cs.CRcs.LG2024-09被引 16

揭露隐私增强联邦学习框架的隐私漏洞,指出其会暴露所有用户梯度。

Comments on "Privacy-Enhanced Federated Learning Against Poisoning Adversaries"

  • 通过分析发现PEFL系统将所有用户梯度明文暴露给参与方之一
  • 即使修复提议也存在多重设计缺陷,无法真正实现隐私保护
  • 适合关注联邦学习安全与隐私的研究者阅读警示

2021年8月,Liu等人(IEEE TIFS'21)提出一种名为PEFL的隐私增强框架,利用同态加密高效检测联邦学习中的投毒行为。本文指出,PEFL并未真正保护隐私:其会将所有用户的完整梯度向量明文暴露给一个参与实体,严重违反隐私要求。此外,我们明确指出,针对该问题提出的即时修复方案仍存在多个设计缺陷,无法实现真正的隐私保护。值得注意的是,尽管我们在2023年1月(Schneider et al., IEEE TIFS'23)已公开上述隐私问题,仍有后续多篇论文继续引用Liu等人(IEEE TIFS'21)的工作作为私有联邦学习的可行方案。部分工作虽承认相关担忧,但仍有大量研究沿用其构造,无意中继承相同隐私漏洞。我们认为此现象部分源于我们2023年评论论文在TIFS上的可见性有限。为防止错误算法在后续研究中持续传播,本文亦提交至ePrint。

原文摘要 · Abstract (English)

In August 2021, Liu et al. (IEEE TIFS'21) proposed a privacy-enhanced framework named PEFL to efficiently detect poisoning behaviours in Federated Learning (FL) using homomorphic encryption. In this article, we show that PEFL does not preserve privacy. In particular, we illustrate that PEFL reveals the entire gradient vector of all users in clear to one of the participating entities, thereby violating privacy. Furthermore, we clearly show that an immediate fix for this issue is still insufficient to achieve privacy by pointing out multiple flaws in the proposed system. Note: Although our privacy issues mentioned in Section II have been published in January 2023 (Schneider et. al., IEEE TIFS'23), several subsequent papers continued to reference Liu et al. (IEEE TIFS'21) as a potential solution for private federated learning. While a few works have acknowledged the privacy concerns we raised, several of subsequent works either propagate these errors or adopt the constructions from Liu et al. (IEEE TIFS'21), thereby unintentionally inheriting the same privacy vulnerabilities. We believe this oversight is partly due to the limited visibility of our comments paper at TIFS'23 (Schneider et. al., IEEE TIFS'23). Consequently, to prevent the continued propagation of the flawed algorithms in Liu et al. (IEEE TIFS'21) into future research, we also put this article to an ePrint.

联邦学习隐私保护安全漏洞

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。