提出检测联邦学习中恶意服务器梯度泄露的防御方法
Hear No Evil: Detecting Gradient Leakage by Malicious Servers in Federated Learning
- 从防御者视角分析恶意服务器诱导的梯度泄露攻击
- 发现攻击效果与隐蔽性存在根本矛盾,现实中易被察觉
- 设计轻量级客户端检测机制,可提前识别异常模型更新
近期研究显示,联邦学习(FL)中的梯度更新可能无意泄露客户端本地数据的敏感信息。当恶意服务器操纵全局模型以诱导客户端产生信息丰富的更新时,这一风险显著加剧。本文从防御者角度首次全面分析了此类恶意梯度泄露攻击及其背后模型操控技术。研究揭示一个核心权衡:这些攻击无法同时具备高重建私有数据的能力和足够的隐蔽性,尤其在包含常见归一化技术和联邦平均(Federated Averaging)的现实设置中更为明显。基于此,我们认为尽管理论上有担忧,但实际中这类攻击具有内在局限且通常可被基础监控发现。作为补充贡献,我们提出一种简单、轻量、广泛适用的客户端侧检测机制,可在本地训练前标记可疑模型更新——尽管在真实场景下该检测可能并非严格必要。该机制进一步证明,仅以极小开销即可实现有效防御,为注重隐私的联邦学习系统提供可部署的安全保障。
原文摘要 · Abstract (English)
Recent work has shown that gradient updates in federated learning (FL) can unintentionally reveal sensitive information about a client's local data. This risk becomes significantly greater when a malicious server manipulates the global model to provoke information-rich updates from clients. In this paper, we adopt a defender's perspective to provide the first comprehensive analysis of malicious gradient leakage attacks and the model manipulation techniques that enable them. Our investigation reveals a core trade-off: these attacks cannot be both highly effective in reconstructing private data and sufficiently stealthy to evade detection -- especially in realistic FL settings that incorporate common normalization techniques and federated averaging. Building on this insight, we argue that malicious gradient leakage attacks, while theoretically concerning, are inherently limited in practice and often detectable through basic monitoring. As a complementary contribution, we propose a simple, lightweight, and broadly applicable client-side detection mechanism that flags suspicious model updates before local training begins, despite the fact that such detection may not be strictly necessary in realistic FL settings. This mechanism further underscores the feasibility of defending against these attacks with minimal overhead, offering a deployable safeguard for privacy-conscious federated learning systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。