Stealing Split Learning Bottom Models by Recovering Embedding Geometry
Qinbo Zhang, Yanhang Shi, Ziyi Zhang, Hao Wang, Sai Qian Zhang, Jian Li
Abstract
Vertical federated learning (VFL) trains models by splitting computation across clients and a server that only exchange intermediate embeddings. Recent work shows that a server even if honest-but-curious can steal a client's bottom model by querying the system and regressing on the returned embeddings, and in response, defenses perturb or decouple the embedding channel. We show these defenses remain vulnerable. We propose VENOM, a geometry-aware stealing attack. VENOM first learns a contrastive space over server-observed embeddings, then builds a neighborhood graph and trains a surrogate bottom model to match targets and respect local geometry via a neighbor-matching loss alongside pointwise and feature-shape alignment. This strategy preserves the relational structure that defenses fail to erase, effectively recoupling the embeddings produced by multi-branch and noise-based defenses. Across six datasets, VENOM consistently outperforms standard stealing methods under no defense and multiple defenses, and remains effective with out-of-distribution (OOD) auxiliary data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3e86f60b-c23b-49f8-b7b4-0cae6657f7ccBuilds on9
- SplitFed: When Federated Learning Meets Split LearningChandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Camtepe, Lichao SunAAAI 2022 · 863 citations
- A Coupled Design of Exploiting Record Similarity for Practical Vertical Federated LearningZhaomin Wu, Qinbin Li, Bingsheng HeNeurIPS 2022 · 26 citations
- Bucks for Buckets (B4B): Active Defenses Against Stealing EncodersJan Dubinski, Stanislaw Pawlak, Franziska Boenisch, Tomasz Trzcinski et al.NeurIPS 2023 · 12 citations
- HaCore: Efficient Coreset Construction with Locality Sensitive Hashing for Vertical Federated LearningQinbo Zhang, Xiao Yan, Yukai Ding, Fangcheng Fu et al.AAAI 2025 · 3 citations
- Hounding Data Diversity: Towards Participant Selection in Vertical Federated LearningXiaokai Zhou, Xiao Yan, Fangcheng Fu, Xinyan Li et al.ICDE 2025 · 1 citation
Related papers
- URVFL: Undetectable Data Reconstruction Attack on Vertical Federated LearningDuanyi Yao, Songze Li, Xueluan Gong, Sizai Hou et al.NDSS 2025
- VILLAIN: Backdoor Attacks Against Vertical Split LearningYijie Bai, Yanjiao Chen, Hanlei Zhang, Wenyuan Xu et al.USENIX Security 2023
- Label-Free Backdoor Attacks in Vertical Federated LearningWei Shen, Wenke Huang, Guancheng Wan, Mang YeAAAI 2025 · 15 citations
- Generic Adversarial Attack Framework Against Graph-based Vertical Federated LearningYimin Liu, Peng Jiang, Qi Liu, Liehuang ZhuAAAI 2026
- Preventing Strategic Behaviors in Collaborative Inference for Vertical Federated LearningYidan Xing, Zhenzhe Zheng, Fan WuKDD 2024 · 1 citation
