提出一种可重构输入的攻击,揭示功能加密训练中的隐私漏洞。
Functional Encryption in Secure Neural Network Training: Data Leakage and Practical Mitigations
- 用线性规划逆向重建加密数据输入
- 发现现有加密训练方案存在可被利用的隐私泄露
- 提出两种客户端参与的新防护方案,适合云上模型训练场景
随着人工智能的发展,机器学习即服务(MLaaS)在云端提供了便捷的模型训练、测试和部署基础设施。然而,将敏感数据上传至云端进行训练带来了重大隐私风险。因此,实现安全的神经网络训练成为研究热点。目前多数解决方案围绕功能加密(Functional Encryption, FE)构建。尽管这些方法为加密数据上的机器学习训练提供了新思路,但某些潜在漏洞未被充分考虑。本文提出一种针对使用FE进行安全训练的神经网络的攻击,通过线性规划重构原始输入,暴露了原有安全承诺的脆弱性。为应对该攻击,我们提出两种新的安全训练与推理方案,均要求客户端参与计算阶段。一种方案不依赖加密,另一种采用函数隐藏型内积技术,有效提升了安全性。
原文摘要 · Abstract (English)
With the increased interest in artificial intelligence, Machine Learning as a Service provides the infrastructure in the Cloud for easy training, testing, and deploying models. However, these systems have a major privacy issue: uploading sensitive data to the Cloud, especially during training. Therefore, achieving secure Neural Network training has been on many researchers' minds lately. More and more solutions for this problem are built around a main pillar: Functional Encryption (FE). Although these approaches are very interesting and offer a new perspective on ML training over encrypted data, some vulnerabilities do not seem to be taken into consideration. In our paper, we present an attack on neural networks that uses FE for secure training over encrypted data. Our approach uses linear programming to reconstruct the original input, unveiling the previous security promises. To address the attack, we propose two solutions for secure training and inference that involve the client during the computation phase. One approach ensures security without relying on encryption, while the other uses function-hiding inner-product techniques.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。