arXiv:2512.12840cs.LGcs.AI2025-12

提出PRIVEE防御垂直联邦学习中的特征推断攻击

PRIVEE: Privacy-Preserving Vertical Federated Learning Against Feature Inference Attacks

  • 通过变换置信度分数,隐藏原始数据特征
  • 使特征重建误差提升30倍,预测性能不变
  • 适合隐私敏感的跨机构联合建模场景

垂直联邦学习(VFL)使拥有共同用户但不同特征空间的组织可协同训练模型。然而,VFL易受特征推断攻击:恶意参与方利用推理阶段共享的置信度分数(预测概率)重构其他方的私有输入特征。为此,本文提出PRIVEE(PRIvacy-preserving Vertical fEderated lEarning),以法语词privée(私密)命名。PRIVEE在保持相对排序和分数间距离等关键性质的前提下,对置信度分数进行混淆,仅分享变换后的表示,从而降低特征重构风险,且不影响模型预测准确率。大量实验表明,相较于最强现有防御,PRIVEE在对抗先进特征推断攻击时,重建误差(MSE)最高提升30倍,同时保持完整预测性能。

原文摘要 · Abstract (English)

Vertical Federated Learning (VFL) enables collaborative model training across organizations that share common user samples but hold disjoint feature spaces. Despite its potential, VFL is susceptible to feature inference attacks, in which adversarial parties exploit shared confidence scores (prediction probabilities) during inference to reconstruct private input features of other participants. To counter this threat, we propose PRIVEE (PRIvacy-preserving Vertical fEderated lEarning), a novel defense mechanism named after the French word privée, meaning "private." PRIVEE obfuscates confidence scores while preserving critical properties such as relative ranking and inter-score distances. Rather than exposing raw scores, PRIVEE only shares transformed representations, mitigating risk of reconstruction attacks without degrading model prediction accuracy. Extensive experiments show that PRIVEE achieves up to a 30 times increase in reconstruction error (MSE) against feature inference attacks, compared to the strongest competing defense, while preserving full predictive performance against advanced feature inference attacks.

联邦学习隐私保护特征推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。