梳理分裂学习的攻击与防御体系,揭示安全风险与应对策略。
A Taxonomy of Attacks and Defenses in Split Learning
- 按策略、约束、效果三维度分类攻击与防御方法
- 系统总结现有威胁类型及防御机制有效性差异
- 指出隐私泄露与模型倒推等关键挑战,适合安全研究者参考
分裂学习(Split Learning, SL)作为一种分布式深度学习范式,使资源受限的客户端可将部分模型计算卸载至服务器,实现协同学习。然而,近期研究表明SL仍面临多种隐私与安全威胁,包括信息泄露、模型反演和对抗攻击。尽管已有多种防御机制被提出,但对攻击场景与对应防护措施的系统性理解仍不足。本文构建了一个全面的攻击与防御分类体系,从所用策略、约束条件和实际效果三个维度进行归纳。基于此系统化分析,我们识别出若干关键开放问题与研究空白,指明未来潜在发展方向。
原文摘要 · Abstract (English)
Split Learning (SL) has emerged as a promising paradigm for distributed deep learning, allowing resource-constrained clients to offload portions of their model computation to servers while maintaining collaborative learning. However, recent research has demonstrated that SL remains vulnerable to a range of privacy and security threats, including information leakage, model inversion, and adversarial attacks. While various defense mechanisms have been proposed, a systematic understanding of the attack landscape and corresponding countermeasures is still lacking. In this study, we present a comprehensive taxonomy of attacks and defenses in SL, categorizing them along three key dimensions: employed strategies, constraints, and effectiveness. Furthermore, we identify key open challenges and research gaps in SL based on our systematization, highlighting potential future directions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。