arXiv:2412.12837cs.LGcs.DC2024-12中稿 · Middleware'25, 13 …被引 2

发现去中心化学习中图混合特性影响成员推理攻击风险

Exposing the Vulnerability of Decentralized Learning to Membership Inference Attacks Through the Lens of Graph Mixing

  • 通过分析节点间通信图结构与模型混合策略,揭示隐私漏洞根源
  • 不同图结构下,攻击成功率最高达78%,与全局混合效率强相关
  • 为去中心化系统设计提供降低隐私风险的实证指导

去中心化学习允许多方协作训练模型而不共享原始数据,但需交换模型参数或梯度,可能被用于成员推理攻击(MIA)泄露敏感信息。本文通过改变通信图结构(如邻居数量)、图动态性和聚合策略,在多个数据集和数据分布下系统评估各类去中心化架构对MIA的脆弱性。关键发现:攻击成功率与节点本地模型混合策略及通信图的全局混合特性高度相关。实验基于四个数据集验证,并结合理论分析证明提升图混合性能可显著增强隐私保护效果,尤其在与差分隐私结合时更为有效。本文总结出降低去中心化学习系统隐私风险的设计原则。

原文摘要 · Abstract (English)

The primary promise of decentralized learning is to allow users to engage in the training of machine learning models in a collaborative manner while keeping their data on their premises and without relying on any central entity. However, this paradigm necessitates the exchange of model parameters or gradients between peers. Such exchanges can be exploited to infer sensitive information about training data, which is achieved through privacy attacks (e.g., Membership Inference Attacks -- MIA). In order to devise effective defense mechanisms, it is important to understand the factors that increase/reduce the vulnerability of a given decentralized learning architecture to MIA. In this study, we extensively explore the vulnerability to MIA of various decentralized learning architectures by varying the graph structure (e.g., number of neighbors), the graph dynamics, and the aggregation strategy, across diverse datasets and data distributions. Our key finding, which to the best of our knowledge we are the first to report, is that the vulnerability to MIA is heavily correlated to (i) the local model mixing strategy performed by each node upon reception of models from neighboring nodes and (ii) the global mixing properties of the communication graph. We illustrate these results experimentally using four datasets and by theoretically analyzing the mixing properties of various decentralized architectures. We also empirically show that enhancing mixing properties is highly beneficial when combined with other privacy-preserving techniques such as Differential Privacy. Our paper draws a set of lessons learned for devising decentralized learning systems that reduce by design the vulnerability to MIA.

去中心化学习成员推理攻击图神经网络隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。