arXiv:2502.08151cs.CRcs.LG2025-02被引 9

提出新攻击方法,突破本地差分隐私防护,重建联邦学习中的敏感样本

Local Differential Privacy is Not Enough: A Sample Reconstruction Attack against Federated Learning with Local Differential Privacy

  • 利用梯度压缩与去噪机制,在隐私保护下还原用户原始数据
  • 在真实模型上实现高质量样本重建,且不影响模型准确率
  • 揭示当前隐私防护的漏洞,适合研究隐私安全与对抗攻击者

针对联邦学习中的样本重构攻击,现有方法在引入本地差分隐私(LDP)后失效,因梯度裁剪与扰动会破坏大部分样本信息。同时,已有攻击通过向梯度中注入额外信息提升效果,导致梯度膨胀,加剧了裁剪问题。本文提出一种新型重构攻击,适用于任意目标模型,可在基于LDP的联邦学习中重建受害者敏感样本,证明其并非完全安全。核心思路为梯度压缩与重建样本去噪:通过基于样本特征的推理结构减少冗余梯度;通过人工引入零梯度观察噪声分布,动态缩放置信区间以过滤噪声。理论证明攻击有效性。实验表明,该攻击是唯一能在基于LDP的联邦学习中成功重构训练样本的方法,且对目标模型准确率影响极小。结论指出,当前基于LDP的联邦学习仍需改进以有效防御样本重构攻击。

原文摘要 · Abstract (English)

Reconstruction attacks against federated learning (FL) aim to reconstruct users' samples through users' uploaded gradients. Local differential privacy (LDP) is regarded as an effective defense against various attacks, including sample reconstruction in FL, where gradients are clipped and perturbed. Existing attacks are ineffective in FL with LDP since clipped and perturbed gradients obliterate most sample information for reconstruction. Besides, existing attacks embed additional sample information into gradients to improve the attack effect and cause gradient expansion, leading to a more severe gradient clipping in FL with LDP. In this paper, we propose a sample reconstruction attack against LDP-based FL with any target models to reconstruct victims' sensitive samples to illustrate that FL with LDP is not flawless. Considering gradient expansion in reconstruction attacks and noise in LDP, the core of the proposed attack is gradient compression and reconstructed sample denoising. For gradient compression, an inference structure based on sample characteristics is presented to reduce redundant gradients against LDP. For reconstructed sample denoising, we artificially introduce zero gradients to observe noise distribution and scale confidence interval to filter the noise. Theoretical proof guarantees the effectiveness of the proposed attack. Evaluations show that the proposed attack is the only attack that reconstructs victims' training samples in LDP-based FL and has little impact on the target model's accuracy. We conclude that LDP-based FL needs further improvements to defend against sample reconstruction attacks effectively.

联邦学习隐私攻击差分隐私样本重建

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。