arXiv:2601.06641cs.LGcs.CR2026-01被引 1

提出针对联邦提示调优的隐私攻击,可精准判断数据是否在客户端中。

Leveraging Soft Prompts for Privacy Attacks in Federated Prompt Tuning

  • 利用恶意服务器注入对抗性提示,监控更新来推断隐私数据
  • 在多个数据集上攻击成功率高,理论分析支持其实效性
  • 现有防御方法对提示调优攻击效果差,需专门设计新防御

成员推理攻击(MIA)在联邦学习中构成重大隐私威胁,允许攻击者判断某客户端私有数据集中是否包含特定样本。尽管标准联邦学习中的此类攻击已有充分研究,但近年来向联邦微调的转变引入了新的、尚未被充分探索的攻击面。本文揭示了联邦提示调优这一新兴范式下的漏洞:该方法通过小规模输入前缀适配预训练模型以提升效率,却也暴露了新的隐私攻击路径。我们提出 PromptMIA,一种专为联邦提示调优设计的成员推理攻击,其中恶意服务器可插入对抗性提示,并在协同训练过程中监测其更新,从而准确判断目标数据点是否存在于客户端私有数据集中。我们将此威胁形式化为安全博弈,并实证表明,PromptMIA 在多种基准数据集上均表现出显著优势。理论分析进一步给出了攻击优势的下界,解释并支撑了实验中观察到的高攻击成功率。我们还评估了原有基于梯度或输出的防御机制在应对 PromptMIA 时的有效性,发现其在提示调优的威胁场景下存在明显局限,凸显当前防御策略的不足,强调需为联邦提示调优场景定制专门的防御方案。

原文摘要 · Abstract (English)

Membership inference attack (MIA) poses a significant privacy threat in federated learning (FL) as it allows adversaries to determine whether a client's private dataset contains a specific data sample. While defenses against membership inference attacks in standard FL have been well studied, the recent shift toward federated fine-tuning has introduced new, largely unexplored attack surfaces. To highlight this vulnerability in the emerging FL paradigm, we demonstrate that federated prompt-tuning, which adapts pre-trained models with small input prefixes to improve efficiency, also exposes a new vector for privacy attacks. We propose PromptMIA, a membership inference attack tailored to federated prompt-tuning, in which a malicious server can insert adversarially crafted prompts and monitors their updates during collaborative training to accurately determine whether a target data point is in a client's private dataset. We formalize this threat as a security game and empirically show that PromptMIA consistently attains high advantage in this game across diverse benchmark datasets. Our theoretical analysis further establishes a lower bound on the attack's advantage which explains and supports the consistently high advantage observed in our empirical results. We also investigate the effectiveness of standard membership inference defenses originally developed for gradient or output based attacks and analyze their interaction with the distinct threat landscape posed by PromptMIA. The results highlight non-trivial challenges for current defenses and offer insights into their limitations, underscoring the need for defense strategies that are specifically tailored to prompt-tuning in federated settings.

联邦学习隐私攻击提示调优成员推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。