arXiv:2506.17292cs.CRcs.AI2025-06ICML

即使使用LDP保护,联邦视觉模型仍可能被成员推断攻击攻破。

Theoretically Unmasking Inference Attacks Against LDP-Protected Clients in Federated Vision Models

  • 从理论上推导出低多项式时间攻击的最低成功率边界。
  • 实验表明LDP保护下攻击成功率仍高,且噪声会严重降低模型性能。
  • 适合关注隐私安全与模型实用性平衡的研究者参考。

联邦学习通过协调服务器实现客户端间的协作学习,避免直接共享数据,被认为可保护隐私。然而,近期关于成员推断攻击(MIAs)的研究挑战了这一观点,显示对未受保护训练数据的攻击成功率很高。尽管局部差分隐私(LDP)被视为数据分析中的隐私保护金标准,但大多数关于MIAs的研究要么忽略LDP,要么未能为针对LDP保护数据的攻击成功率提供理论保证。为此,我们推导出利用全连接层或自注意力层漏洞的低多项式时间成员推断攻击的成功率理论下界。结果表明,即使数据经过LDP保护,隐私风险依然存在,且取决于隐私预算。在联邦视觉模型上的实际评估证实了显著的隐私风险,揭示出缓解此类攻击所需的噪声会大幅降低模型效用。

原文摘要 · Abstract (English)

Federated Learning enables collaborative learning among clients via a coordinating server while avoiding direct data sharing, offering a perceived solution to preserve privacy. However, recent studies on Membership Inference Attacks (MIAs) have challenged this notion, showing high success rates against unprotected training data. While local differential privacy (LDP) is widely regarded as a gold standard for privacy protection in data analysis, most studies on MIAs either neglect LDP or fail to provide theoretical guarantees for attack success rates against LDP-protected data. To address this gap, we derive theoretical lower bounds for the success rates of low-polynomial time MIAs that exploit vulnerabilities in fully connected or self-attention layers. We establish that even when data are protected by LDP, privacy risks persist, depending on the privacy budget. Practical evaluations on federated vision models confirm considerable privacy risks, revealing that the noise required to mitigate these attacks significantly degrades models' utility.

隐私安全联邦学习差分隐私成员推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。