arXiv:2505.20924cs.LGcs.HC2025-05

联邦学习中人体动作识别易泄露标签,攻击成功率超90%。

Label Leakage in Federated Inertial-based Human Activity Recognition

  • 用梯度反推输入标签,验证了联邦哈动作识别的隐私风险
  • 在两个基准数据集上标签重建准确率超90%,即使模型已训练
  • 本地差分隐私防护效果有限,仍可恢复多数与少数类别标签

尽管已有研究指出联邦学习更新可能泄露敏感信息,但针对人体动作识别(HAR)场景的基于梯度的标签重构攻击尚未被充分探讨。鉴于动作标签具有高度敏感性,本研究评估了当前最先进的梯度类标签泄露攻击在HAR基准数据集上的有效性。结果表明,动作类别数、采样策略和类别不平衡是影响标签泄露程度的关键因素,在两个基准数据集上,即便模型已训练完成,标签重建准确率仍远超90%。此外,我们发现局部差分隐私技术如梯度噪声添加和截断仅提供有限保护,某些攻击仍能可靠推断出多数类和少数类标签。研究最后提出联邦哈动作识别系统隐私部署的实用建议,并指明未来研究的开放挑战。实验代码已公开于github.com/mariusbock/leakage_har。

原文摘要 · Abstract (English)

While prior work has shown that Federated Learning updates can leak sensitive information, label reconstruction attacks, which aim to recover input labels from shared gradients, have not yet been examined in the context of Human Activity Recognition (HAR). Given the sensitive nature of activity labels, this study evaluates the effectiveness of state-of-the-art gradient-based label leakage attacks on HAR benchmark datasets. Our findings show that the number of activity classes, sampling strategy, and class imbalance are critical factors influencing the extent of label leakage, with reconstruction accuracies reaching well-above 90% on two benchmark datasets, even for trained models. Moreover, we find that Local Differential Privacy techniques such as gradient noise and clipping offer only limited protection, as certain attacks still reliably infer both majority and minority class labels. We conclude by offering practical recommendations for the privacy-aware deployment of federated HAR systems and identify open challenges for future research. Code to reproduce our experiments is publicly available via github.com/mariusbock/leakage_har.

联邦学习隐私安全动作识别梯度泄露

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。