首个针对联邦遗忘系统的数据重建攻击框架,揭示主流方法的隐私漏洞。
DRAUN: An Algorithm-Agnostic Data Reconstruction Attack on Federated Unlearning Systems
- 设计算法无关的重建框架,利用客户端更新逆向还原被删除数据。
- 在四数据集四模型上验证,五种主流遗忘方法均遭成功重建。
- 为合规性提供新风险警示,适合关注联邦学习隐私的研究者。
联邦遗忘(FU)使客户端能够移除特定数据对联合训练全局模型的影响,满足如GDPR和CCPA等法规要求。然而,该遗忘过程引入了新隐私风险:恶意服务器可能利用遗忘更新重建被请求删除的数据,即数据重建攻击(DRA)。尽管集中式机器学习即服务(MLaaS)场景下的数据重建攻击已有广泛研究,但其在去中心化、客户端主导的联邦遗忘系统中的适用性尚不明确。本文提出DRAUN,首个针对联邦遗忘系统重建未学习数据的攻击框架。该框架针对广泛采用的基于优化的遗忘方法,理论上证明现有针对机器遗忘的攻击在联邦场景下失效的原因,并展示如何克服这些限制。通过在四个数据集和四种模型架构上的大量实验,评估了其对五种主流遗忘方法的有效性,充分表明当前最先进的联邦遗忘方法仍易受数据重建攻击影响。
原文摘要 · Abstract (English)
Federated Unlearning (FU) enables clients to remove the influence of specific data from a collaboratively trained shared global model, addressing regulatory requirements such as GDPR and CCPA. However, this unlearning process introduces a new privacy risk: A malicious server may exploit unlearning updates to reconstruct the data requested for removal, a form of Data Reconstruction Attack (DRA). While DRAs for machine unlearning have been studied extensively in centralized Machine Learning-as-a-Service (MLaaS) settings, their applicability to FU remains unclear due to the decentralized, client-driven nature of FU. This work presents DRAUN, the first attack framework to reconstruct unlearned data in FU systems. DRAUN targets optimization-based unlearning methods, which are widely adopted for their efficiency. We theoretically demonstrate why existing DRAs targeting machine unlearning in MLaaS fail in FU and show how DRAUN overcomes these limitations. We validate our approach through extensive experiments on four datasets and four model architectures, evaluating its performance against five popular unlearning methods, effectively demonstrating that state-of-the-art FU methods remain vulnerable to DRAs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。