arXiv:2501.03119cs.LGcs.AI2025-01被引 5

攻击者仅凭模型行为就能推断去中心化联邦学习的网络结构。

From Models to Network Topologies: A Topology Inference Attack in Decentralized Federated Learning

  • 通过分析各节点模型行为,逆向推导出去中心化联邦学习的连接拓扑。
  • 实验表明仅用节点模型即可准确还原整个网络结构。
  • 揭示了去中心化联邦学习中的新隐私风险,适合安全研究者关注。

联邦学习(FL)因其不直接交换数据而被视为一种保护隐私的机器学习范式。然而,模型训练过程会留下可被利用的痕迹,从而泄露敏感信息。在去中心化联邦学习(DFL)中,参与者之间的连接拓扑对模型隐私、鲁棒性和收敛性具有关键影响。但该拓扑也引入了未被充分认识的漏洞:攻击者可利用它推断参与方的关系并发动针对性攻击。本文提出一种新型拓扑推断攻击,仅依靠模型行为即可推断出网络拓扑结构,并构建了基于攻击者能力与知识水平的攻击分类体系。针对不同场景设计了实用攻击策略,通过实验识别出影响攻击成功率的关键因素。结果表明,仅分析每个节点的模型即可准确重构出整个DFL拓扑,凸显了现有系统中的严重隐私风险。研究为提升去中心化联邦学习环境下的隐私保护提供了重要启示。

原文摘要 · Abstract (English)

Federated Learning (FL) is widely recognized as a privacy-preserving Machine Learning paradigm due to its model-sharing mechanism that avoids direct data exchange. Nevertheless, model training leaves exploitable traces that can be used to infer sensitive information. In Decentralized FL (DFL), the topology, defining how participants are connected, plays a crucial role in shaping the model's privacy, robustness, and convergence. However, the topology introduces an unexplored vulnerability: attackers can exploit it to infer participant relationships and launch targeted attacks. This work uncovers the hidden risks of DFL topologies by proposing a novel Topology Inference Attack that infers the topology solely from model behavior. A taxonomy of topology inference attacks is introduced, categorizing them by the attacker's capabilities and knowledge. Practical attack strategies are designed for various scenarios, and experiments are conducted to identify key factors influencing attack success. The results demonstrate that analyzing only the model of each node can accurately infer the DFL topology, highlighting a critical privacy risk in DFL systems. These findings offer insights for improving privacy preservation in DFL environments.

联邦学习隐私攻击拓扑推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。