arXiv:2506.11413cs.LGcs.CR2025-06

恶意客户端利用梯度操纵反向重建他人数据,暴露联邦学习隐私漏洞。

Byzantine Outside, Curious Inside: Reconstructing Data Through Malicious Updates

  • 设计新型攻击模型:恶意客户端通过篡改梯度实现数据逆向重构。
  • 实验显示,错误使用防御机制可使重建图像质量提升10%-15%。
  • 现有防护手段在该攻击下失效,甚至可能加剧数据泄露。

联邦学习(FL)允许多方在不共享原始数据的情况下协同训练模型,但研究发现,隐私泄露仍可能发生。尤其当服务器能访问客户端梯度时,可合成出与客户端训练数据相似的数据。本文提出一种新型威胁模型——恶意好奇客户端,即客户端主动操纵自身梯度,以推断其他参与方的私有数据。该攻击者利用拜占庭对手的特性,将其从破坏模型鲁棒性转为支持数据重建。我们形式化定义了该模型并进行理论分析,证明其在训练过程中具备显著重建能力。进一步提出结合梯度反演与恶意更新策略的重构算法。实验表明,当前主流的服务器端鲁棒聚合和客户端隐私保护机制均无法有效抵御此攻击;令人意外的是,部分标准防御措施反而会无意中加剧数据泄露,导致重建图像质量提升10%-15%。

原文摘要 · Abstract (English)

Federated learning (FL) enables decentralized machine learning without sharing raw data, allowing multiple clients to collaboratively learn a global model. However, studies reveal that privacy leakage is possible under commonly adopted FL protocols. In particular, a server with access to client gradients can synthesize data resembling the clients' training data. In this paper, we introduce a novel threat model in FL, named the maliciously curious client, where a client manipulates its own gradients with the goal of inferring private data from peers. This attacker uniquely exploits the strength of a Byzantine adversary, traditionally aimed at undermining model robustness, and repurposes it to facilitate data reconstruction attack. We begin by formally defining this novel client-side threat model and providing a theoretical analysis that demonstrates its ability to achieve significant reconstruction success during FL training. To demonstrate its practical impact, we further develop a reconstruction algorithm that combines gradient inversion with malicious update strategies. Our analysis and experimental results reveal a critical blind spot in FL defenses: both server-side robust aggregation and client-side privacy mechanisms may fail against our proposed attack. Surprisingly, standard server- and client-side defenses designed to enhance robustness or privacy may unintentionally amplify data leakage. Compared to the baseline approach, a mistakenly used defense may instead improve the reconstructed image quality by 10-15%.

联邦学习隐私泄露数据重建拜占庭攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。