Effective passive membership inference attacks in federated learning against overparameterized models
Jiacheng Li, Ninghui Li, Bruno Ribeiro
Abstract
This work considers the challenge of performing membership inference attacks in a federated learning setting ---for image classification--- where an adversary can only observe the communication between the central node and a single client (a passive white-box attack). Passive attacks are one of the hardest-to-detect attacks, since they can be performed without modifying how the behavior of the central server or its clients, and assumes no access to private data instances. The key insight of our method is empirically observing that, near parameters that generalize well in test, the gradient of large overparameterized neural network models statistically behave like high-dimensional independent isotropic random vectors. Using this insight, we devise two attacks that are often little impacted by existing and proposed defenses. Finally, we validated the hypothesis that our attack depends on the overparametrization by showing that increasing the level of overparametrization (without changing the neural network architecture) positively correlates with our attack effectiveness.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8a4363ed-1653-4c99-8a14-2df5187fcbceCited by top-tier papers8
- MIST: Defending Against Membership Inference Attacks Through Membership-Invariant Subspace TrainingJiacheng Li, Ninghui Li, Bruno RibeiroUSENIX Security 2024 · 16 citations
- Efficient Privacy Auditing in Federated LearningHongyan Chang, Brandon Edwards, Anindya S. Paul, Reza ShokriUSENIX Security 2024 · 9 citations
- FLUX: Efficient Descriptor-Driven Clustered Federated Learning under Arbitrary Distribution ShiftsDario Fenoglio, Mohan Li, Pietro Barbiero, Nicholas D. Lane et al.NeurIPS 2025 · 8 citations
- Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual ApproachGuilin Deng, Silong Chen, Yuchuan Luo, Yi Liu et al.S&P 2026 · 4 citations
- Federated Learning with Profile Mapping under Distribution Shifts and DriftsMohan Li, Dario Fenoglio, Martin Gjoreski, Marc LangheinrichICLR 2026 · 2 citations
Related papers
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Stolen Memories: Leveraging Model Memorization for Calibrated White-Box Membership InferenceKlas Leino, Matt FredriksonUSENIX Security 2020
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Theoretically Unmasking Inference Attacks Against LDP-Protected Clients in Federated Vision ModelsQuan Minh Nguyen, Minh N. Vu, Truc Nguyen, My T. ThaiICML 2025
- FedMIA: An Effective Membership Inference Attack Exploiting "All for One" Principle in Federated LearningGongxi Zhu, Donghao Li, Hanlin Gu, Yuan Yao et al.CVPR 2025
