Unleashing the Tiger: Inference Attacks on Split Learning
Dario Pasquini, Giuseppe Ateniese, Massimo Bernaschi
Abstract
We investigate the security of split learning---a novel collaborative machine learning framework that enables peak performance by requiring minimal resource consumption. In the present paper, we expose vulnerabilities of the protocol and demonstrate its inherent insecurity by introducing general attack strategies targeting the reconstruction of clients' private training sets. More prominently, we show that a malicious server can actively hijack the learning process of the distributed model and bring it into an insecure state that enables inference attacks on clients' data. We implement different adaptations of the attack and test them on various datasets as well as within realistic threat scenarios. We demonstrate that our attack can overcome recently proposed defensive techniques aimed at enhancing the security of the split learning protocol. Finally, we also illustrate the protocol's insecurity against malicious clients by extending previously devised attacks for Federated Learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 47499d56-aba3-45c4-9d01-075e9959e5b6Cited by top-tier papers29
- Falcon: A Privacy-Preserving and Interpretable Vertical Federated Learning SystemYuncheng Wu, Naili Xing, Gang Chen, Tien Tuan Anh Dinh et al.VLDB 2023 · 47 citations
- BadVFL: Backdoor Attacks in Vertical Federated LearningMohammad Naseri, Yufei Han, Emiliano De CristofaroS&P 2024 · 29 citations
- Bounding the Invertibility of Privacy-preserving Instance Encoding using Fisher InformationKiwan Maeng, Chuan Guo, Sanjay Kariyappa, G. Edward SuhNeurIPS 2023 · 22 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Safely Learning with Private Data: A Federated Learning Framework for Large Language ModelJiaying Zheng, Hainan Zhang, Lingxiang Wang, Wangjie Qiu et al.EMNLP 2024 · 18 citations
Builds on8
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
- SplitFed: When Federated Learning Meets Split LearningChandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Camtepe, Lichao SunAAAI 2022 · 863 citations
Related papers
- PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client AttackXinben Gao, Lan ZhangUSENIX Security 2023
- Chronic Poisoning: Backdoor Attack against Split LearningFangchao Yu, Bo Zeng, Kai Zhao, Zhi Pang et al.AAAI 2024 · 15 citations
- On the (In)security of Peer-to-Peer Decentralized Machine LearningDario Pasquini, Mathilde Raynal, Carmela TroncosoS&P 2023
- Robust and Actively Secure Serverless Collaborative LearningNicholas Franzese, Adam Dziedzic, Christopher A. Choquette-Choo, Mark R. Thomas et al.NeurIPS 2023 · 7 citations
- Focusing on Pinocchio's Nose: A Gradients Scrutinizer to Thwart Split-Learning Hijacking Attacks Using Intrinsic AttributesJiayun Fu, Xiaojing Ma, Bin B. Zhu, Pingyi Hu et al.NDSS 2023
