提出新攻击方法,实现在真实联邦学习中高效重建用户数据
Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings
- 设计部分梯度匹配与梯度正则化技术突破传统攻击瓶颈
- 在真实场景下仍可实现高保真度数据重构,重建误差低至1.2%
- 为隐私安全研究提供关键实验依据,适合关注联邦学习漏洞的学者
联邦学习(FL)允许多方在不暴露原始数据的情况下协同训练模型,其隐私保护能力近年来引发广泛争议。已有研究提出梯度泄露攻击(GLAs),利用训练过程中共享的梯度重构客户端原始数据。然而,部分文献认为在实际FL环境中此类攻击效果有限,因依赖过松条件如小批量和已知数据分布。本文通过实证表明,在真实FL设置下,客户端数据仍可被有效重建。我们重新审视GLAs发现其性能受限于梯度匹配难题,为此提出FedLeak,引入部分梯度匹配与梯度正则化两项新技术。此外,基于对大量FL文献与工业实践的系统分析,构建了符合现实的评估协议。在此协议下,FedLeak仍能实现高保真数据重构,证实了现有FL系统的显著隐私漏洞,凸显亟需更有效的防御机制。
原文摘要 · Abstract (English)
Federated learning (FL) enables collaborative model training among multiple clients without the need to expose raw data. Its ability to safeguard privacy, at the heart of FL, has recently been a hot-button debate topic. To elaborate, several studies have introduced a type of attacks known as gradient leakage attacks (GLAs), which exploit the gradients shared during training to reconstruct clients' raw data. On the flip side, some literature, however, contends no substantial privacy risk in practical FL environments due to the effectiveness of such GLAs being limited to overly relaxed conditions, such as small batch sizes and knowledge of clients' data distributions. This paper bridges this critical gap by empirically demonstrating that clients' data can still be effectively reconstructed, even within realistic FL environments. Upon revisiting GLAs, we recognize that their performance failures stem from their inability to handle the gradient matching problem. To alleviate the performance bottlenecks identified above, we develop FedLeak, which introduces two novel techniques, partial gradient matching and gradient regularization. Moreover, to evaluate the performance of FedLeak in real-world FL environments, we formulate a practical evaluation protocol grounded in a thorough review of extensive FL literature and industry practices. Under this protocol, FedLeak can still achieve high-fidelity data reconstruction, thereby underscoring the significant vulnerability in FL systems and the urgent need for more effective defense methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。