Focusing on Pinocchio's Nose: A Gradients Scrutinizer to Thwart Split-Learning Hijacking Attacks Using Intrinsic Attributes
Jiayun Fu, Xiaojing Ma, Bin B. Zhu, Pingyi Hu, Ruixin Zhao, Yaru Jia, Peng Xu, Hai Jin, Dongmei Zhang
Abstract
—Split learning is privacy-preserving distributed learning that has gained momentum recently. It also faces new security challenges. FSHA [37] is a serious threat to split learning. In FSHA, a malicious server hijacks training to trick clients to train the encoder of an autoencoder instead of a classification model. Intermediate results sent to the server by a client are actually latent codes of private training samples, which can be reconstructed with high fidelity from the received codes with the decoder of the autoencoder. SplitGuard [10] is the only existing effective defense against hijacking attacks. It is an active method that injects falsely labeled data to incur abnormal behaviors to detect hijacking attacks. Such injection also incurs an adverse impact on honest training of intended models. In this paper, we first show that SplitGuard is vulnerable to an adaptive hijacking attack named SplitSpy. SplitSpy exploits the same property that SplitGuard exploits to detect hijacking attacks. In SplitSpy, a malicious server maintains a shadow model that performs the intended task to detect falsely labeled data and evade SplitGuard. Our experimental evaluation indicates that SplitSpy can effectively evade SplitGuard. Then we propose a novel passive detection method, named Gradients Scrutinizer, which relies on intrinsic differences between gradients from an intended model and those from a malicious model: the expected similarity among gradients of same-label samples differs from the expected similarity among gradients of different-label samples for an intended model, while they are the same for a malicious model. This intrinsic distinguishability
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9a57b5cb-d94d-473a-b4ba-abfee7b1dce2Cited by top-tier papers5
- Chronic Poisoning: Backdoor Attack against Split LearningFangchao Yu, Bo Zeng, Kai Zhao, Zhi Pang et al.AAAI 2024 · 15 citations
- A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningXiaoyang Xu, Mengda Yang, Wenzhe Yi, Ziang Li et al.CVPR 2024 · 13 citations
- SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split LearningPhillip Rieger, Alessandro Pegoraro, Kavita Kumari, Tigist Abera et al.NDSS 2025
- URVFL: Undetectable Data Reconstruction Attack on Vertical Federated LearningDuanyi Yao, Songze Li, Xueluan Gong, Sizai Hou et al.NDSS 2025
- Passive Inference Attacks on Split Learning via Adversarial RegularizationXiaochen Zhu, Xinjian Luo, Yuncheng Wu, Yangfan Jiang et al.NDSS 2025
Builds on5
- SplitFed: When Federated Learning Meets Split LearningChandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Camtepe, Lichao SunAAAI 2022 · 863 citations
- Group Knowledge Transfer: Federated Learning of Large CNNs at the EdgeChaoyang He, Murali Annavaram, Salman AvestimehrNeurIPS 2020 · 605 citations
- Deep Learning with Label Differential PrivacyBadih Ghazi, Noah Golowich, Ravi Kumar, Pasin Manurangsi et al.NeurIPS 2021 · 193 citations
- Label Leakage and Protection in Two-party Split LearningOscar Li, Jiankai Sun, Xin Yang, Weihao Gao et al.ICLR 2022 · 170 citations
- Unleashing the Tiger: Inference Attacks on Split LearningDario Pasquini, Giuseppe Ateniese, Massimo BernaschiCCS 2021 · 14 citations
Related papers
- SecureSplit: Mitigating Backdoor Attacks in Split LearningZhihao Dou, Dongfei Cui, Weida Wang, Anjun Gao et al.WWW 2026 · 1 citation
- HealSplit: Towards Self-Healing Through Adversarial Distillation in Split Federated LearningYuhan Xie, Chen LyuAAAI 2026
- ZORRO: Zero-Knowledge Robustness and Privacy for Split LearningNojan Sheybani, Alessandro Pegoraro, Jonathan Knauer, Phillip Rieger et al.CCS 2025
- PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client AttackXinben Gao, Lan ZhangUSENIX Security 2023
- DualGuard: A Parameter Space Transformation Approach for Bidirectional Defense in Split-Based LLM Fine-TuningZihan Liu, Yizhen Wang, Rui Wang, Sai WuACL 2025
