arXiv:2410.04661cs.LGcs.CR2024-10被引 1

联邦学习中一个节点可悄悄重建其他节点的图像数据

Federated Learning Nodes Can Reconstruct Peers' Image Data

  • 利用连续梯度更新中的稀疏信息进行图像反演
  • 单个节点即可重建他人隐私图像,且质量接近真实
  • 扩散模型提升重建图像的语义可识别性,风险更高

联邦学习(FL)是一种保护隐私的机器学习框架,允许多个节点在本地数据上训练模型,并定期平均权重更新以共享知识。各节点目标是在不泄露训练数据的前提下协作提升模型性能。然而,该框架无法保障数据隐私。已有研究指出,诚实但好奇的中央服务器可通过梯度共享环节发起数据重构攻击。本文首次证明,诚实但好奇的客户端同样能通过梯度反演对其他客户端的图像数据实施攻击,造成严重隐私风险。我们演示了仅凭连续更新中稀疏的信息,单个客户端即可无声地重构他人私有图像。通过引入最先进的扩散模型,显著提升了重构图像的视觉质量和语义可辨识度,进一步揭示了语义层面的信息泄露风险。这凸显了需要更鲁棒的隐私保护机制,以防御联邦训练过程中的隐蔽客户端攻击。

原文摘要 · Abstract (English)

Federated learning (FL) is a privacy-preserving machine learning framework that enables multiple nodes to train models on their local data and periodically average weight updates to benefit from other nodes' training. Each node's goal is to collaborate with other nodes to improve the model's performance while keeping its training data private. However, this framework does not guarantee data privacy. Prior work has shown that the gradient-sharing steps in FL can be vulnerable to data reconstruction attacks from an honest-but-curious central server. In this work, we show that an honest-but-curious node/client can also launch attacks to reconstruct peers' image data through gradient inversion, presenting a severe privacy risk. We demonstrate that a single client can silently reconstruct other clients' private images using diluted information available within consecutive updates. We leverage state-of-the-art diffusion models to enhance the perceptual quality and recognizability of the reconstructed images, further demonstrating the risk of information leakage at a semantic level. This highlights the need for more robust privacy-preserving mechanisms that protect against silent client-side attacks during federated training.

联邦学习隐私攻击图像重建

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。