提出联邦遗忘反向攻击,揭示遗忘机制中的隐私漏洞
Model Inversion Attack against Federated Unlearning
- 利用遗忘前后模型差异反推被删数据特征与标签
- 在三种遗忘类型中均成功恢复隐私信息,泄露率显著
- 适合关注联邦学习隐私安全的研究者和开发者
随着“被遗忘权”相关法规的出台,联邦学习(FL)面临新的隐私合规挑战。为应对这一问题,研究者提出了联邦遗忘(FU)。然而,现有研究主要关注遗忘效率提升,较少关注方法本身潜在的隐私风险。为此,我们借鉴联邦学习中的梯度反向攻击思想,提出联邦遗忘反向攻击(FUIA),专门针对样本遗忘、客户端遗忘和类别遗忘三类场景,全面分析其隐私泄露风险。在FUIA中,服务器作为诚实但好奇的攻击者,通过记录并分析遗忘前后的模型差异,还原被遗忘数据的特征与标签。实验表明,该攻击能有效暴露被遗忘数据的私密信息,违背了联邦遗忘消除特定数据影响的初衷,反而利用其机制恢复敏感内容。我们还探索了两种防御方案,但会降低遗忘效果与模型可用性。
原文摘要 · Abstract (English)
With the introduction of regulations related to the ``right to be forgotten", federated learning (FL) is facing new privacy compliance challenges. To address these challenges, researchers have proposed federated unlearning (FU). However, existing FU research has primarily focused on improving the efficiency of unlearning, with less attention paid to the potential privacy vulnerabilities inherent in these methods. To address this gap, we draw inspiration from gradient inversion attacks in FL and propose the federated unlearning inversion attack (FUIA). The FUIA is specifically designed for the three types of FU (sample unlearning, client unlearning, and class unlearning), aiming to provide a comprehensive analysis of the privacy leakage risks associated with FU. In FUIA, the server acts as an honest-but-curious attacker, recording and exploiting the model differences before and after unlearning to expose the features and labels of forgotten data. FUIA significantly leaks the privacy of forgotten data and can target all types of FU. This attack contradicts the goal of FU to eliminate specific data influence, instead exploiting its vulnerabilities to recover forgotten data and expose its privacy flaws. Extensive experimental results show that FUIA can effectively reveal the private information of forgotten data. To mitigate this privacy leakage, we also explore two potential defense methods, although these come at the cost of reduced unlearning effectiveness and the usability of the unlearned model.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。