arXiv:2504.02114cs.CRcs.AI2025-04被引 4

研究联邦学习中模型更新如何被窃听者破解,提出保护客户端模型的新思路。

On Model Protection in Federated Learning against Eavesdropping Attacks

  • 分析客户端选择概率、本地目标函数结构等因素对模型泄露的影响
  • 实验表明窃听者可重建高精度模型,威胁模型安全
  • 对比差分隐私发现其在此场景下防护效果有限,适合关注模型安全的研究者

本研究探讨联邦学习算法对窃听攻击的防护能力。在该模型中,攻击者可截获客户端上传至服务器的模型更新,进而构建自身模型估计。与以往聚焦保护客户端数据的工作不同,本文关注保护客户端模型本身。通过理论分析,研究了客户端选择概率、本地目标函数结构、服务器全局聚合方式及攻击者能力等要素对整体防护水平的影响。数值实验验证了结论,以攻击者重建模型的准确率评估防护效果。最后,将结果与差分隐私方法对比,揭示其在该场景下的局限性。

原文摘要 · Abstract (English)

In this study, we investigate the protection offered by federated learning algorithms against eavesdropping adversaries. In our model, the adversary is capable of intercepting model updates transmitted from clients to the server, enabling it to create its own estimate of the model. Unlike previous research, which predominantly focuses on safeguarding client data, our work shifts attention protecting the client model itself. Through a theoretical analysis, we examine how various factors, such as the probability of client selection, the structure of local objective functions, global aggregation at the server, and the eavesdropper's capabilities, impact the overall level of protection. We further validate our findings through numerical experiments, assessing the protection by evaluating the model accuracy achieved by the adversary. Finally, we compare our results with methods based on differential privacy, underscoring their limitations in this specific context.

联邦学习模型安全窃听攻击隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。