Stealing Split Learning Bottom Models by Recovering Embedding Geometry
Qinbo Zhang, Yanhang Shi, Ziyi Zhang, Hao Wang, Sai Qian Zhang, Jian Li
摘要
Vertical federated learning (VFL) trains models by splitting computation across clients and a server that only exchange intermediate embeddings. Recent work shows that a server even if honest-but-curious can steal a client's bottom model by querying the system and regressing on the returned embeddings, and in response, defenses perturb or decouple the embedding channel. We show these defenses remain vulnerable. We propose VENOM, a geometry-aware stealing attack. VENOM first learns a contrastive space over server-observed embeddings, then builds a neighborhood graph and trains a surrogate bottom model to match targets and respect local geometry via a neighbor-matching loss alongside pointwise and feature-shape alignment. This strategy preserves the relational structure that defenses fail to erase, effectively recoupling the embeddings produced by multi-branch and noise-based defenses. Across six datasets, VENOM consistently outperforms standard stealing methods under no defense and multiple defenses, and remains effective with out-of-distribution (OOD) auxiliary data.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- SplitFed: When Federated Learning Meets Split LearningChandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Camtepe, Lichao SunAAAI 2022 · 被引用 863 次
- A Coupled Design of Exploiting Record Similarity for Practical Vertical Federated LearningZhaomin Wu, Qinbin Li, Bingsheng HeNeurIPS 2022 · 被引用 26 次
- Bucks for Buckets (B4B): Active Defenses Against Stealing EncodersJan Dubinski, Stanislaw Pawlak, Franziska Boenisch, Tomasz Trzcinski 等NeurIPS 2023 · 被引用 12 次
- HaCore: Efficient Coreset Construction with Locality Sensitive Hashing for Vertical Federated LearningQinbo Zhang, Xiao Yan, Yukai Ding, Fangcheng Fu 等AAAI 2025 · 被引用 3 次
- Hounding Data Diversity: Towards Participant Selection in Vertical Federated LearningXiaokai Zhou, Xiao Yan, Fangcheng Fu, Xinyan Li 等ICDE 2025 · 被引用 1 次
相关 Paper
- URVFL: Undetectable Data Reconstruction Attack on Vertical Federated LearningDuanyi Yao, Songze Li, Xueluan Gong, Sizai Hou 等NDSS 2025
- VILLAIN: Backdoor Attacks Against Vertical Split LearningYijie Bai, Yanjiao Chen, Hanlei Zhang, Wenyuan Xu 等USENIX Security 2023
- Label-Free Backdoor Attacks in Vertical Federated LearningWei Shen, Wenke Huang, Guancheng Wan, Mang YeAAAI 2025 · 被引用 15 次
- Generic Adversarial Attack Framework Against Graph-based Vertical Federated LearningYimin Liu, Peng Jiang, Qi Liu, Liehuang ZhuAAAI 2026
- Preventing Strategic Behaviors in Collaborative Inference for Vertical Federated LearningYidan Xing, Zhenzhe Zheng, Fan WuKDD 2024 · 被引用 1 次
