arXiv:2411.14937cs.LGcs.AI2024-11ICCV被引 8

用自然语言精准定位并重建联邦学习中的隐私数据

Geminio: Language-Guided Gradient Inversion Attacks in Federated Learning

  • 利用视觉语言模型引导梯度反演,实现语义级目标攻击
  • 可在大批次下成功重建指定关键词的高价值图像
  • 攻击隐蔽性强,不影响正常训练,适合隐私漏洞研究

视觉语言模型(VLM)在提升多模态应用的同时,也带来了新的隐私威胁。本文揭示了可利用预训练的VLM增强联邦学习(FL)中的梯度反演攻击(GIA),使攻击者能通过自然语言描述目标数据,精准重构特定样本。传统方法在大规模本地数据上重建效果差,而本研究提出Geminio,首次实现语义可控的靶向攻击:攻击者输入查询文本,系统自动优化恶意全局模型,仅保留与查询匹配的客户端梯度。该攻击可任意轮次发起,且不干扰正常训练,仍能生成高质量模型。大量实验表明,在复杂数据集和大批次条件下,其重建成功率高,对防御手段具有强鲁棒性。

原文摘要 · Abstract (English)

Foundation models that bridge vision and language have made significant progress. While they have inspired many life-enriching applications, their potential for abuse in creating new threats remains largely unexplored. In this paper, we reveal that vision-language models (VLMs) can be weaponized to enhance gradient inversion attacks (GIAs) in federated learning (FL), where an FL server attempts to reconstruct private data samples from gradients shared by victim clients. Despite recent advances, existing GIAs struggle to reconstruct high-resolution images when the victim has a large local data batch. One promising direction is to focus reconstruction on valuable samples rather than the entire batch, but current methods lack the flexibility to target specific data of interest. To address this gap, we propose Geminio, the first approach to transform GIAs into semantically meaningful, targeted attacks. It enables a brand new privacy attack experience: attackers can describe, in natural language, the data they consider valuable, and Geminio will prioritize reconstruction to focus on those high-value samples. This is achieved by leveraging a pretrained VLM to guide the optimization of a malicious global model that, when shared with and optimized by a victim, retains only gradients of samples that match the attacker-specified query. Geminio can be launched at any FL round and has no impact on normal training (i.e., the FL server can steal clients' data while still producing a high-utility ML model as in benign scenarios). Extensive experiments demonstrate its effectiveness in pinpointing and reconstructing targeted samples, with high success rates across complex datasets and large batch sizes with resilience against defenses.

联邦学习隐私攻击视觉语言模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。