arXiv:2601.06200cs.CRcs.AI2026-01

用成员推理攻击量化联邦学习在遥感图像中的隐私泄露风险

Leveraging Membership Inference Attacks for Privacy Measurement in Federated Learning for Remote Sensing Images

  • 以成员推理攻击为工具,量化联邦学习中隐私泄露程度
  • 通信高效策略可降低攻击成功率,同时保持模型性能
  • 适合关注遥感数据隐私保护的研究者和系统设计者

联邦学习(FL)可在保护训练数据本地性的同时实现协同建模,适用于遥感等隐私敏感领域。然而,近期研究表明,FL模型仍可能通过输出泄露敏感信息,亟需严格的隐私评估。本文将成员推理攻击(MIA)作为量化隐私度量框架,应用于遥感图像分类任务。在两个公开场景分类数据集上,评估了基于熵、改进熵及似然比等多种黑盒MIA方法,在不同FL算法与通信策略下的表现。实验表明,MIA能有效揭示仅靠准确率无法捕捉的隐私泄露问题。结果还显示,通信高效的FL策略可降低MIA成功率,同时保持良好性能。研究证实MIA是实用的隐私度量指标,强调在遥感应用中集成隐私评估的重要性。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative model training while keeping training data localized, allowing us to preserve privacy in various domains including remote sensing. However, recent studies show that FL models may still leak sensitive information through their outputs, motivating the need for rigorous privacy evaluation. In this paper, we leverage membership inference attacks (MIA) as a quantitative privacy measurement framework for FL applied to remote sensing image classification. We evaluate multiple black-box MIA techniques, including entropy-based attacks, modified entropy attacks, and the likelihood ratio attack, across different FL algorithms and communication strategies. Experiments conducted on two public scene classification datasets demonstrate that MIA effectively reveals privacy leakage not captured by accuracy alone. Our results show that communication-efficient FL strategies reduce MIA success rates while maintaining competitive performance. These findings confirm MIA as a practical metric and highlight the importance of integrating privacy measurement into FL system design for remote sensing applications.

联邦学习隐私保护遥感图像成员推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。