简单模型变换即可有效防护垂直联邦学习中的数据泄露
Just a Simple Transformation is Enough for Data Protection in Vertical Federated Learning
- 通过改变模型结构实现数据保护,无需复杂加密
- MLP模型对主流特征重建攻击完全免疫
- 适合关注隐私安全的工业级联邦学习应用
垂直联邦学习(VFL)旨在实现深度学习模型的协作训练,同时保障隐私。然而,现有VFL流程仍存在被恶意方攻击的风险。本文聚焦于特征重建攻击——一种针对输入数据泄露的常见威胁。理论上证明,若缺乏数据先验分布知识,特征重建攻击无法成功。实验验证表明,即使采用简单的模型架构变换,也能显著提升输入数据安全性。特别地,基于MLP的模型对当前最先进的特征重建攻击具有完全抵抗力。
原文摘要 · Abstract (English)
Vertical Federated Learning (VFL) aims to enable collaborative training of deep learning models while maintaining privacy protection. However, the VFL procedure still has components that are vulnerable to attacks by malicious parties. In our work, we consider feature reconstruction attacks, a common risk targeting input data compromise. We theoretically claim that feature reconstruction attacks cannot succeed without knowledge of the prior distribution on data. Consequently, we demonstrate that even simple model architecture transformations can significantly impact the protection of input data during VFL. Confirming these findings with experimental results, we show that MLP-based models are resistant to state-of-the-art feature reconstruction attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。