剖析联邦学习中梯度反演攻击的漏洞与防御策略
Exploring the Vulnerabilities of Federated Learning: A Deep Dive into Gradient Inversion Attacks
- 将梯度反演攻击分为优化、生成、分析三类,系统分类研究
- 发现优化类攻击最实用但效果一般,生成与分析类依赖多且易被检测
- 提出三阶段防御框架,助力设计更安全的联邦学习系统
联邦学习(FL)作为一种无需共享原始数据即可协同训练模型的隐私保护范式,近年来受到广泛关注。然而,近期研究表明,通过共享的梯度信息仍可能泄露私有信息,面临梯度反演攻击(GIA)威胁。尽管已有多种GIA方法被提出,但对其系统性分析、评估与总结仍显不足。现有综述多聚焦于隐私攻击汇总,缺乏对各类GIA在实际场景中有效性及限制因素的深入实验。为此,本文首次对GIA进行系统梳理,将其分为三类:基于优化的GIA(OP-GIA)、基于生成的GIA(GEN-GIA)和基于分析的GIA(ANA-GIA)。通过全面分析与评估,揭示影响其性能、实用性及潜在威胁的关键因素。结果表明,尽管性能有限,OP-GIA仍是当前最实用的攻击方式;而GEN-GIA存在多重依赖,ANA-GIA则易被检测,二者均不具实用性。最后,我们为用户设计FL框架与协议提供了一个三阶段防御流程,并从攻防双视角提出若干未来研究方向,旨在推动更鲁棒的联邦学习隐私保护体系构建。
原文摘要 · Abstract (English)
Federated Learning (FL) has emerged as a promising privacy-preserving collaborative model training paradigm without sharing raw data. However, recent studies have revealed that private information can still be leaked through shared gradient information and attacked by Gradient Inversion Attacks (GIA). While many GIA methods have been proposed, a detailed analysis, evaluation, and summary of these methods are still lacking. Although various survey papers summarize existing privacy attacks in FL, few studies have conducted extensive experiments to unveil the effectiveness of GIA and their associated limiting factors in this context. To fill this gap, we first undertake a systematic review of GIA and categorize existing methods into three types, i.e., \textit{optimization-based} GIA (OP-GIA), \textit{generation-based} GIA (GEN-GIA), and \textit{analytics-based} GIA (ANA-GIA). Then, we comprehensively analyze and evaluate the three types of GIA in FL, providing insights into the factors that influence their performance, practicality, and potential threats. Our findings indicate that OP-GIA is the most practical attack setting despite its unsatisfactory performance, while GEN-GIA has many dependencies and ANA-GIA is easily detectable, making them both impractical. Finally, we offer a three-stage defense pipeline to users when designing FL frameworks and protocols for better privacy protection and share some future research directions from the perspectives of attackers and defenders that we believe should be pursued. We hope that our study can help researchers design more robust FL frameworks to defend against these attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。