arXiv:2508.10598cs.LG2025-08被引 4

系统分析分裂学习的各类攻击,揭示隐私漏洞并评估防御方案

Oops!... They Stole it Again: Attacks on Split Learning

  • 按攻击者角色、隐私风险等维度分类梳理攻击类型
  • 发现现有防御手段存在局限性,部分方法无法有效应对特定攻击
  • 适合关注联邦学习安全、隐私保护的研究者与开发者阅读

分裂学习(Split Learning, SL)是一种通过将数据保留在客户端而仅向服务器共享中间输出来提升隐私保护的协作学习方法。然而,其分布式特性引入了新的安全挑战,亟需对潜在攻击进行全面探索。本文系统性地回顾了针对SL的各种攻击,根据攻击者角色、隐私风险类型、数据泄露时机及漏洞位置等因素进行分类。同时分析了现有的防御方法,包括加密技术、数据扰动、分布式策略以及混合方案。研究结果揭示了当前防御机制中存在的安全缺口,明确了其有效性与局限性。通过识别开放性挑战与未来研究方向,本工作为改善分裂学习的隐私保护问题提供了重要参考,并指导后续研究。

原文摘要 · Abstract (English)

Split Learning (SL) is a collaborative learning approach that improves privacy by keeping data on the client-side while sharing only the intermediate output with a server. However, the distributed nature of SL introduces new security challenges, necessitating a comprehensive exploration of potential attacks. This paper systematically reviews various attacks on SL, classifying them based on factors such as the attacker's role, the type of privacy risks, when data leaks occur, and where vulnerabilities exist. We also analyze existing defense methods, including cryptographic methods, data modification approaches, distributed techniques, and hybrid solutions. Our findings reveal security gaps, highlighting the effectiveness and limitations of existing defenses. By identifying open challenges and future directions, this work provides valuable information to improve SL privacy issues and guide further research.

分裂学习隐私安全攻击分析联邦学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。