arXiv:2506.03207cs.LGcs.AI2025-06中稿 · publish in Proceed…被引 3

通过网络流量分析可精准识别联邦学习中的模型架构。

Fingerprinting Deep Learning Models via Network Traffic Patterns in Federated Learning

  • 利用机器学习分析联邦学习中的网络流量特征。
  • 随机森林实现100%准确率,其他模型达95.7%以上。
  • 揭示了联邦学习的隐蔽安全风险,适合安全研究者关注。

联邦学习(FL)因其在不集中用户数据的前提下训练模型而被广泛采用,有效保护了数据隐私。然而,现有研究未充分关注通过网络流量分析导致的间接隐私泄露问题。本文旨在探究在联邦学习环境中,通过分析网络层流量信息是否可实现深度学习模型的指纹识别。我们在一个联邦学习测试平台中,对多种深度学习架构(如CNN、RNN)进行了实验评估,并采用支持向量机(SVM)、随机森林(Random Forest)和梯度提升(Gradient-Boosting)等机器学习算法分析流量数据。实验结果表明,随机森林达到100%的指纹识别准确率,而SVM与梯度提升分类器分别达到约95.7%的准确率。这说明可从网络流量中识别出特定模型架构。若攻击者知晓底层模型结构,便能实施针对性攻击。该研究揭示了联邦学习系统在网络安全层面的重大漏洞,亟需在网络层加强防护。

原文摘要 · Abstract (English)

Federated Learning (FL) is increasingly adopted as a decentralized machine learning paradigm due to its capability to preserve data privacy by training models without centralizing user data. However, FL is susceptible to indirect privacy breaches via network traffic analysis-an area not explored in existing research. The primary objective of this research is to study the feasibility of fingerprinting deep learning models deployed within FL environments by analyzing their network-layer traffic information. In this paper, we conduct an experimental evaluation using various deep learning architectures (i.e., CNN, RNN) within a federated learning testbed. We utilize machine learning algorithms, including Support Vector Machines (SVM), Random Forest, and Gradient-Boosting, to fingerprint unique patterns within the traffic data. Our experiments show high fingerprinting accuracy, achieving 100% accuracy using Random Forest and around 95.7% accuracy using SVM and Gradient Boosting classifiers. This analysis suggests that we can identify specific architectures running within the subsection of the network traffic. Hence, if an adversary knows about the underlying DL architecture, they can exploit that information and conduct targeted attacks. These findings suggest a notable security vulnerability in FL systems and the necessity of strengthening it at the network level.

联邦学习模型指纹隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。