arXiv:2604.12737cs.CRcs.LG2026-04被引 1

用堆叠攻击评估联邦学习中差分隐私的隐私保护效果

Evaluating Differential Privacy Against Membership Inference in Federated Learning: Insights from the NIST Genomics Red Team Challenge

论文配图:Evaluating Differential Privacy Against Membership Inference in Federated Learning: Insights from the NIST Genomics Red Team Challenge
图 1 · 摘自论文原文
  • 设计堆叠攻击,融合七种黑盒估计器提升推理精度
  • 在ε=200时仍存在可测量的成员泄露,ε=10时防护更有效
  • 适用于关注联邦学习隐私安全的研究者和实践者

尽管联邦学习减少了直接的数据暴露,但训练后的模型仍易受成员推断攻击(MIAs)影响。本文基于2025年NIST基因组隐私保护联邦学习红队挑战赛环境,对差分隐私(DP)作为防御机制在联邦学习中抵御成员推断攻击的效果进行了实证评估。为提升推理准确率,提出一种堆叠攻击策略,通过集成七种黑盒估计器,利用预测概率与交叉熵损失训练元分类器。在三种隐私配置下评估:无保护卷积神经网络(CNN,ε=∞)、低隐私DP模型(ε=200)和高隐私DP模型(ε=10)。该攻击在无DP和低隐私设置下优于所有基线,在ε=200时仍保持显著成员泄露,而单信号LiRA基线在此处失效。在第三方独立基准上验证,结果揭示了堆叠式推断在不同校准的差分隐私层级下的退化规律。

原文摘要 · Abstract (English)

While Federated Learning (FL) mitigates direct data exposure, the resulting trained models remain susceptible to membership inference attacks (MIAs). This paper presents an empirical evaluation of Differential Privacy (DP) as a defense mechanism against MIAs in FL, leveraging the environment of the 2025 NIST Genomics Privacy-Preserving Federated Learning (PPFL) Red Teaming Event. To improve inference accuracy, we propose a stacking attack strategy that ensembles seven black-box estimators to train a meta-classifier on prediction probabilities and cross-entropy losses. We evaluate this methodology against target models under three privacy configurations: an unprotected convolutional neural network (CNN, $ε=\infty$), a low-privacy DP model ($ε=200$), and a high-privacy DP model ($ε=10$). The attack outperforms all baselines in the No DP and Low Privacy settings and, critically, maintains measurable membership leakage at $ε=200$ where a single-signal LiRA baseline collapses. Evaluated on an independent third-party benchmark, these results provide an empirical characterisation of how stacking-based inference degrades across calibrated DP tiers in FL.

联邦学习差分隐私成员推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。