arXiv:2506.07605cs.CRcs.DC2025-06

攻击联邦树模型可还原73%以上训练数据,暴露隐私漏洞

TimberStrike: Dataset Reconstruction Attack Revealing Privacy Leakage in Federated Tree-Based Systems

  • 利用决策树分裂值和路径信息,单客户端发起重建攻击
  • 在多种框架上对中风预测数据重建率达73.05%~95.63%
  • 揭示树模型联邦学习隐私缺陷,适合安全与隐私研究者

联邦学习作为隐私保护的分布式机器学习范式,允许在不直接共享数据的情况下协同训练模型。尽管神经网络的联邦学习已广泛研究,树模型的安全与隐私问题仍被忽视。本文提出TimberStrike,一种基于优化的、针对水平联邦树模型的数据集重建攻击。攻击者仅需单个客户端,通过利用决策树的离散特性,结合分裂值与决策路径,推断出其他客户端的敏感训练数据。我们在Flower、NVFlare和FedTree等多个主流框架上评估该攻击,结果显示其对最先进的联邦梯度提升模型均具威胁。在公开的中风预测数据集上,重构准确率稳定在73.05%至95.63%之间。进一步分析差分隐私发现,虽能部分缓解攻击,但显著降低模型性能。研究强调亟需为树模型联邦学习设计专用隐私保护机制,并提供初步设计洞见。

原文摘要 · Abstract (English)

Federated Learning has emerged as a privacy-oriented alternative to centralized Machine Learning, enabling collaborative model training without direct data sharing. While extensively studied for neural networks, the security and privacy implications of tree-based models remain underexplored. This work introduces TimberStrike, an optimization-based dataset reconstruction attack targeting horizontally federated tree-based models. Our attack, carried out by a single client, exploits the discrete nature of decision trees by using split values and decision paths to infer sensitive training data from other clients. We evaluate TimberStrike on State-of-the-Art federated gradient boosting implementations across multiple frameworks, including Flower, NVFlare, and FedTree, demonstrating their vulnerability to privacy breaches. On a publicly available stroke prediction dataset, TimberStrike consistently reconstructs between 73.05% and 95.63% of the target dataset across all implementations. We further analyze Differential Privacy, showing that while it partially mitigates the attack, it also significantly degrades model performance. Our findings highlight the need for privacy-preserving mechanisms specifically designed for tree-based Federated Learning systems, and we provide preliminary insights into their design.

联邦学习隐私攻击树模型数据重建

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。