arXiv:2410.05020cs.LGcs.CR2024-10被引 4

用隐私攻击检测联邦学习中的搭便车者,提升模型训练公平性。

FRIDA: Free-Rider Detection using Privacy Attacks

  • 通过成员推断和属性推断攻击,直接识别真实训练证据。
  • 在多种场景下均有效检测出未真正训练的搭便车者。
  • 适合关注联邦学习安全与参与公平性的研究人员使用。

联邦学习因允许多方在数据和资源有限的情况下协同训练模型而日益流行。然而,与其它协作系统类似,联邦学习易受搭便车者影响——这些参与者从全局模型中获益却未贡献真实训练。搭便车行为破坏学习过程完整性,减缓全局模型收敛,增加诚实参与者的成本。为应对这一挑战,我们提出FRIDA:基于隐私攻击的搭便车检测方法。不同于关注搭便车间接影响的传统方法,FRIDA利用成员推断和属性推断攻击,直接获取客户端真实训练的证据。大量实验表明,FRIDA在多种场景下均表现出色,能有效识别虚假参与。

原文摘要 · Abstract (English)

Federated learning is increasingly popular as it enables multiple parties with limited datasets and resources to train a machine learning model collaboratively. However, similar to other collaborative systems, federated learning is vulnerable to free-riders - participants who benefit from the global model without contributing. Free-riders compromise the integrity of the learning process and slow down the convergence of the global model, resulting in increased costs for honest participants. To address this challenge, we propose FRIDA: free-rider detection using privacy attacks. Instead of focusing on implicit effects of free-riding, FRIDA utilizes membership and property inference attacks to directly infer evidence of genuine client training. Our extensive evaluation demonstrates that FRIDA is effective across a wide range of scenarios.

联邦学习隐私攻击安全检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。