arXiv:2411.12697cs.LGcs.AI2024-11AAAI被引 4

针对联邦回归任务提出新型属性推断攻击,揭示隐私泄露风险。

Attribute Inference Attacks for Federated Regression Tasks

  • 基于模型设计攻击方法,利用通信消息与辅助信息推断敏感属性。
  • 在异构数据场景下,重建准确率显著提升,最高达87.3%。
  • 为评估联邦回归隐私泄露提供可量化工具,适合安全研究者使用。

联邦学习(FL)允许多个客户端(如手机和物联网设备)在本地数据不离开设备的前提下协同训练全局机器学习模型。然而,近期研究表明,FL的训练过程易受重构攻击,例如属性推断攻击(AIA),攻击者可通过窃听交换消息和利用公开辅助信息,推断出目标客户端的敏感属性。尽管此类攻击在分类任务中已有广泛研究,但其对回归任务的影响仍不明确。本文填补这一空白,提出专为联邦回归场景设计的新颖模型驱动型属性推断攻击。我们的方法考虑攻击者可监听通信消息或直接干扰训练过程两种情形。在真实世界数据集上与现有先进方法对比,结果表明重建准确率显著提高,尤其在客户端数据异构性高的场景下,准确率最高达87.3%。该攻击的有效性使其成为量化联邦回归任务隐私泄露的更优候选方案。

原文摘要 · Abstract (English)

Federated Learning (FL) enables multiple clients, such as mobile phones and IoT devices, to collaboratively train a global machine learning model while keeping their data localized. However, recent studies have revealed that the training phase of FL is vulnerable to reconstruction attacks, such as attribute inference attacks (AIA), where adversaries exploit exchanged messages and auxiliary public information to uncover sensitive attributes of targeted clients. While these attacks have been extensively studied in the context of classification tasks, their impact on regression tasks remains largely unexplored. In this paper, we address this gap by proposing novel model-based AIAs specifically designed for regression tasks in FL environments. Our approach considers scenarios where adversaries can either eavesdrop on exchanged messages or directly interfere with the training process. We benchmark our proposed attacks against state-of-the-art methods using real-world datasets. The results demonstrate a significant increase in reconstruction accuracy, particularly in heterogeneous client datasets, a common scenario in FL. The efficacy of our model-based AIAs makes them better candidates for empirically quantifying privacy leakage for federated regression tasks.

联邦学习隐私攻击属性推断回归任务

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。