提出可泛化防御医疗图像梯度反演攻击的新方法
Defending Against Gradient Inversion Attacks for Biomedical Images via Learnable Data Perturbation
- 用可学习的隐空间扰动结合极小极大优化增强隐私
- 使攻击者重建图像分类准确率降低12.5%,原始与重构图像MSE提升超12.4%
- 在保持90%模型精度下有效防御,适用于真实医疗数据场景
医疗数据共享与临床研究合作日益增长,但隐私泄露风险加剧,可能引发误诊和患者识别问题。尽管联邦学习(FL)等隐私保护机器学习技术兴起,仍面临梯度反演攻击威胁。现有防御方法缺乏对医疗数据的通用性,且多基于非医疗数据测试,实用性存疑。本文提出一种基于隐空间可学习扰动与极小极大优化的防御方法,覆盖通用与医学图像数据集。对比两种基线,结果表明该方法在维持约90%客户端分类准确率的前提下,使攻击者重建图像分类准确率下降12.5%,原始与重构图像间均方误差(MSE)提升超过12.4%,验证了其在医疗数据中的可泛化潜力。
原文摘要 · Abstract (English)
The increasing need for sharing healthcare data and collaborating on clinical research has raised privacy concerns. Health information leakage due to malicious attacks can lead to serious problems such as misdiagnoses and patient identification issues. Privacy-preserving machine learning (PPML) and privacy-enhancing technologies, particularly federated learning (FL), have emerged in recent years as innovative solutions to balance privacy protection with data utility; however, they also suffer from inherent privacy vulnerabilities. Gradient inversion attacks constitute major threats to data sharing in federated learning. Researchers have proposed many defenses against gradient inversion attacks. However, current defense methods for healthcare data lack generalizability, i.e., existing solutions may not be applicable to data from a broader range of populations. In addition, most existing defense methods are tested using non-healthcare data, which raises concerns about their applicability to real-world healthcare systems. In this study, we present a defense against gradient inversion attacks in federated learning. We achieve this using latent data perturbation and minimax optimization, utilizing both general and medical image datasets. Our method is compared to two baselines, and the results show that our approach can outperform the baselines with a reduction of 12.5% in the attacker's accuracy in classifying reconstructed images. The proposed method also yields an increase of over 12.4% in Mean Squared Error (MSE) between the original and reconstructed images at the same level of model utility of around 90% client classification accuracy. The results suggest the potential of a generalizable defense for healthcare data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。