arXiv:2512.10296cs.CRcs.AI2025-12中稿 · publication in IEE…被引 4

通过监听加密无线流量,破解联邦学习模型架构,攻击者可窥探模型细节。

FLARE: A Wireless Side-Channel Fingerprinting Attack on Federated Learning

  • 利用无线流量的包级和流级统计特征,推断客户端模型结构。
  • 在封闭场景下准确率超98%,开放场景下仍达91%。
  • 首次实现对联邦学习模型架构的侧信道指纹攻击,适合安全研究者关注。

联邦学习(FL)允许多个设备协同训练模型,同时保护数据隐私。然而,现有研究未关注外部攻击者通过间接手段泄露客户端深度学习模型架构(如卷积神经网络CNN或循环神经网络RNN)的风险。一旦泄露,攻击者可据此实施针对性攻击。本文提出一种新型侧信道指纹攻击方法FLARE,基于对加密无线流量中流级与包级统计特征的分析,实现对联邦学习模型架构的推断。在多种CNN与RNN变体(包括预训练及自定义模型)上,基于IEEE 802.11 Wi-Fi环境的评估表明,FLARE在封闭世界场景下F1得分超过98%,开放世界场景下可达91%。结果表明,不同模型会产生可区分的流量模式,即使在存在硬件、软件和数据异构的真实联邦学习环境中也成立。据我们所知,这是首个通过嗅探加密无线流量实现联邦学习模型架构指纹识别的工作,揭示了当前联邦学习系统中的关键侧信道漏洞。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative model training across distributed devices while safeguarding data and user privacy. However, FL remains susceptible to privacy threats that can compromise data via direct means. That said, indirectly compromising the confidentiality of the FL model architecture (e.g., a convolutional neural network (CNN) or a recurrent neural network (RNN)) on a client device by an outsider remains unexplored. If leaked, this information can enable next-level attacks tailored to the architecture. This paper proposes a novel side-channel fingerprinting attack, leveraging flow-level and packet-level statistics of encrypted wireless traffic from an FL client to infer its deep learning model architecture. We name it FLARE, a fingerprinting framework based on FL Architecture REconnaissance. Evaluation across various CNN and RNN variants-including pre-trained and custom models trained over IEEE 802.11 Wi-Fi-shows that FLARE achieves over 98% F1-score in closed-world and up to 91% in open-world scenarios. These results reveal that CNN and RNN models leak distinguishable traffic patterns, enabling architecture fingerprinting even under realistic FL settings with hardware, software, and data heterogeneity. To our knowledge, this is the first work to fingerprint FL model architectures by sniffing encrypted wireless traffic, exposing a critical side-channel vulnerability in current FL systems.

联邦学习侧信道攻击隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。