arXiv:2505.17092cs.CRcs.LG2025-05被引 2

主动攻击者可无声破坏安全多方计算训练,威胁模型隐私与完整

Covert Attacks on Machine Learning Training in Passively Secure MPC

  • 利用被动安全协议漏洞实施隐蔽主动攻击
  • 可重建原始训练数据并破坏模型完整性
  • 适用于关注隐私与安全的机器学习部署场景

安全多方计算(MPC)使数据所有者能在保护原始数据隐私的前提下联合训练机器学习模型。现有MPC威胁模型分为被动攻击(仅窃听)和主动攻击(篡改行为)。有观点认为,在某些场景下主动安全并非关键,因作弊可能导致声誉损失。本文展示了一系列简单而有效的主动攻击,可在不被察觉的情况下破坏现有的被动安全MPC训练协议,导致模型完整性与隐私泄露,甚至可重建精确训练数据。结果挑战了‘忽略恶意行为威胁合理’的假设,强调在隐私保护机器学习中应采用主动安全协议。

原文摘要 · Abstract (English)

Secure multiparty computation (MPC) allows data owners to train machine learning models on combined data while keeping the underlying training data private. The MPC threat model either considers an adversary who passively corrupts some parties without affecting their overall behavior, or an adversary who actively modifies the behavior of corrupt parties. It has been argued that in some settings, active security is not a major concern, partly because of the potential risk of reputation loss if a party is detected cheating. In this work we show explicit, simple, and effective attacks that an active adversary can run on existing passively secure MPC training protocols, while keeping essentially zero risk of the attack being detected. The attacks we show can compromise both the integrity and privacy of the model, including attacks reconstructing exact training data. Our results challenge the belief that a threat model that does not include malicious behavior by the involved parties may be reasonable in the context of PPML, motivating the use of actively secure protocols for training.

安全计算机器学习安全隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。