EMGAN: Early-Mix-GAN on Extracting Server-Side Model in Split Federated Learning
Jingtao Li, Xing Chen, Li Yang, Adnan Siraj Rakin, Deliang Fan, Chaitali Chakrabarti
Abstract
Split Federated Learning (SFL) is an emerging edge-friendly version of Federated Learning (FL), where clients process a small portion of the entire model. While SFL was considered to be resistant to Model Extraction Attack (MEA) by design, a recent work (Li et al. 2023b) shows it is not necessarily the case. In general, gradient-based MEAs are not effective on a target model that is changing, as is the case in training-from-scratch applications. In this work, we propose a strong MEA during the SFL training phase. The proposed Early-Mix-GAN (EMGAN) attack effectively exploits gradient queries regardless of data assumptions. EMGAN adopts three key components to address the problem of inconsistent gradients. Specifically, it employs (i) Early-learner approach for better adaptability, (ii) Multi-GAN approach to introduce randomness in generator training to mitigate mode collapse, and (iii) ProperMix to effectively augment the limited amount of synthetic data for a better approximation of the target domain data distribution. EMGAN achieves excellent results in extracting server-side models. With only 50 training samples, EMGAN successfully extracts a 5-layer server-side model of VGG-11 on CIFAR-10, with 7% less accuracy than the target model. With zero training data, the extracted model achieves 81.3% accuracy, which is significantly better than the 45.5% accuracy of the model extracted by the SoTA method. The code is available at https://github.com/zlijingtao/SFL-MEA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e745e0a3-9d6e-4874-9393-d970ebffe672Builds on9
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
- SplitFed: When Federated Learning Meets Split LearningChandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Camtepe, Lichao SunAAAI 2022 · 863 citations
- Divergence-aware Federated Self-Supervised LearningWeiming Zhuang, Yonggang Wen, Shuai ZhangICLR 2022 · 123 citations
- Up to 100x Faster Data-Free Knowledge DistillationGongfan Fang, Kanya Mo, Xinchao Wang, Jie Song et al.AAAI 2022 · 103 citations
- ResSFL: A Resistance Transfer Framework for Defending Model Inversion Attack in Split Federated LearningJingtao Li, Adnan Siraj Rakin, Xing Chen, Zhezhi He et al.CVPR 2022 · 70 citations
Related papers
- GIFD: A Generative Gradient Inversion Method with Feature Domain OptimizationHao Fang, Bin Chen, Xuan Wang, Zhi Wang et al.ICCV 2023 · 62 citations
- PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client AttackXinben Gao, Lan ZhangUSENIX Security 2023
- Fast Generation-Based Gradient Leakage Attacks against Highly Compressed GradientsDongyun Xue, Haomiao Yang, Mengyu Ge, Jingwei Li et al.INFOCOM 2023 · 4 citations
- Recovering Labels from Local Updates in Federated LearningHuancheng Chen, Haris VikaloICML 2024 · 9 citations
- Robust Federated Learning for Ubiquitous Computing through Mitigation of Edge-Case Backdoor AttacksFatima Elhattab, Sara Bouchenak, Rania Talbi, Vlad NituUbiComp 2023 · 11 citations
