arXiv:2505.10264cs.LGcs.AI2025-05被引 2

提出新型几何攻击法,可无损重建任意大批次联邦学习数据。

Cutting Through Privacy: A Hyperplane-Based Data Reconstruction Attack in Federated Learning

  • 基于全连接层几何结构设计恶意参数,突破数据分布假设
  • 在图像与表格数据上实现比现有方法大100倍的数据批量重建
  • 适用于高批量场景,适合研究隐私漏洞与防御机制的学者

联邦学习(FL)允许多个客户端在不共享原始数据的情况下协同训练模型,表面看能保护数据隐私。然而,近期研究表明,恶意中央服务器可通过操纵模型更新来重构客户端的私有训练数据。现有数据重构攻击存在显著局限:通常依赖客户端数据分布假设,或当批量大小超过数十样本时性能急剧下降。本文提出一种新攻击方法,利用全连接层的新型几何视角,设计恶意模型参数,可在分类任务中无须任何先验知识,完美恢复任意大规模数据批次。在图像与表格数据集上的大量实验表明,该方法优于现有技术,实现了比当前最优方法大两个数量级的数据批量重建。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative training of machine learning models across distributed clients without sharing raw data, ostensibly preserving data privacy. Nevertheless, recent studies have revealed critical vulnerabilities in FL, showing that a malicious central server can manipulate model updates to reconstruct clients' private training data. Existing data reconstruction attacks have important limitations: they often rely on assumptions about the clients' data distribution or their efficiency significantly degrades when batch sizes exceed just a few tens of samples. In this work, we introduce a novel data reconstruction attack that overcomes these limitations. Our method leverages a new geometric perspective on fully connected layers to craft malicious model parameters, enabling the perfect recovery of arbitrarily large data batches in classification tasks without any prior knowledge of clients' data. Through extensive experiments on both image and tabular datasets, we demonstrate that our attack outperforms existing methods and achieves perfect reconstruction of data batches two orders of magnitude larger than the state of the art.

联邦学习隐私攻击数据重建几何方法

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。