arXiv:2508.11907cs.CRcs.AI2025-08

量化攻击与防护复杂度,揭示联邦学习隐私权衡机制

Deciphering the Interplay between Attack and Protection Complexity in Privacy-Preserving Federated Learning

  • 定义攻击复杂度为还原隐私数据的最低资源需求
  • 发现防护复杂度随模型维度和隐私预算上升而增长
  • 为安全高效的联邦学习系统设计提供理论依据

联邦学习(FL)在保护数据隐私的同时实现协同建模,但易受梯度反演攻击。本文提出新理论框架,量化分析攻击与防护复杂度的相互作用。将‘攻击复杂度’定义为攻击者在误差阈值内重构私有数据所需的最小计算与数据资源;将‘防护复杂度’定义为隐私机制引入的期望失真。基于最大贝叶斯隐私(MBP),推导出防护复杂度的紧致理论边界,表明其随模型维度和隐私预算增加而上升。同时建立攻击复杂度的全面边界,揭示其依赖于隐私泄露、梯度失真、模型维度及隐私水平。研究结果定量揭示了隐私保障、系统效用、攻防成本间的根本权衡,为设计更安全高效的联邦学习系统提供关键洞见。

原文摘要 · Abstract (English)

Federated learning (FL) offers a promising paradigm for collaborative model training while preserving data privacy. However, its susceptibility to gradient inversion attacks poses a significant challenge, necessitating robust privacy protection mechanisms. This paper introduces a novel theoretical framework to decipher the intricate interplay between attack and protection complexities in privacy-preserving FL. We formally define "Attack Complexity" as the minimum computational and data resources an adversary requires to reconstruct private data below a given error threshold, and "Protection Complexity" as the expected distortion introduced by privacy mechanisms. Leveraging Maximum Bayesian Privacy (MBP), we derive tight theoretical bounds for protection complexity, demonstrating its scaling with model dimensionality and privacy budget. Furthermore, we establish comprehensive bounds for attack complexity, revealing its dependence on privacy leakage, gradient distortion, model dimension, and the chosen privacy level. Our findings quantitatively illuminate the fundamental trade-offs between privacy guarantees, system utility, and the effort required for both attacking and defending. This framework provides critical insights for designing more secure and efficient federated learning systems.

联邦学习隐私保护攻击防御理论分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。