arXiv:2411.03019cs.CRcs.CV2024-11被引 3

构建真实联邦场景下的深度泄漏攻击与防御评测框架

FEDLAD: Federated Evaluation of Deep Leakage Attacks and Defenses

  • 统一整合多种主流深度泄漏攻击与防御方法
  • 在多个数据集和训练状态下评估攻防效果差异
  • 揭示隐私与模型精度间的权衡,推动可复现研究

联邦学习是一种隐私保护的分布式机器学习范式,通过在客户端间交换梯度而非共享原始数据来协同训练模型。然而,近期研究表明其安全性存在漏洞:攻击者可通过梯度反演技术(即深度泄漏)恢复出私有数据。尽管已有相关攻击方法提出,但大多未在真实联邦环境中进行评估。本文提出FEDLAD框架(联邦学习中深度泄漏攻击与防御的评估),建立了一个涵盖多种前沿深度泄漏攻击及防御策略的统一基准。该框架支持在不同数据集和训练状态下的攻防效果对比,揭示了联邦学习中隐私与模型准确率之间的关键权衡。本工作旨在深化对去中心化机器学习安全挑战的理解,推动未来研究并提升相关评测的可复现性。

原文摘要 · Abstract (English)

Federated Learning is a privacy preserving decentralized machine learning paradigm designed to collaboratively train models across multiple clients by exchanging gradients to the server and keeping private data local. Nevertheless, recent research has revealed that the security of Federated Learning is compromised, as private ground truth data can be recovered through a gradient inversion technique known as Deep Leakage. While these attacks are crafted with a focus on applications in Federated Learning, they generally are not evaluated in realistic scenarios. This paper introduces the FEDLAD Framework (Federated Evaluation of Deep Leakage Attacks and Defenses), a comprehensive benchmark for evaluating Deep Leakage attacks and defenses within a realistic Federated context. By implementing a unified benchmark that encompasses multiple state-of-the-art Deep Leakage techniques and various defense strategies, our framework facilitates the evaluation and comparison of the efficacy of these methods across different datasets and training states. This work highlights a crucial trade-off between privacy and model accuracy in Federated Learning and aims to advance the understanding of security challenges in decentralized machine learning systems, stimulate future research, and enhance reproducibility in evaluating Deep Leakage attacks and defenses.

联邦学习隐私安全攻防评测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。