A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split Learning
Xiaoyang Xu, Mengda Yang, Wenzhe Yi, Ziang Li, Juan Wang, Hongxin Hu, Yong Zhuang, Yaxin Liu
摘要
Split Learning (SL) is a distributed learning framework renowned for its privacy-preserving features and minimal computational requirements. Previous research consistently highlights the potential privacy breaches in SL systems by server adversaries reconstructing training data. However, these studies often rely on strong assumptions or compromise system utility to enhance attack performance. This paper introduces a new semi-honest Data Reconstruction Attack on SL, named Feature-Oriented Reconstruction Attack (FORA). In contrast to prior works, FORA relies on limited prior knowledge, specifically that the server utilizes auxiliary samples from the public without knowing any client's private information. This allows FORA to conduct the attack stealthily and achieve robust performance. The key vulnerability exploited by FORA is the revelation of the model representation preference in the smashed data output by victim client. FORA constructs a substitute client through feature-level transfer learning, aiming to closely mimic the victim client's representation preference. Leveraging this substitute client, the server trains the attack model to effectively reconstruct private data. Extensive experiments showcase FORA's superior performance compared to state-of-the-art methods. Furthermore, the paper systematically evaluates the proposed method's applicability across diverse settings and advanced defense strategies.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- CapRecover: A Cross-Modality Feature Inversion Attack Framework on Vision Language ModelsKedong Xiu, Sai Qian ZhangACM MM 2025 · 被引用 2 次
- From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed LearningZiang Li, Hongguang Zhang, Juan Wang, Meihui Chen 等CVPR 2025
- Split Adaptation for Pre-trained Vision TransformersLixu Wang, Bingqi Shang, Yi Li, Payal Mohapatra 等CVPR 2025
- DRAG: Data Reconstruction Attack using Guided DiffusionWa-Kin Lei, Jun-Cheng Chen, Shang-Tse ChenICML 2025
它引用的顶会 Paper16
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- SplitFed: When Federated Learning Meets Split LearningChandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Camtepe, Lichao SunAAAI 2022 · 被引用 863 次
- Overlearning Reveals Sensitive AttributesCongzheng Song, Vitaly ShmatikovICLR 2020 · 被引用 177 次
相关 Paper
- PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client AttackXinben Gao, Lan ZhangUSENIX Security 2023
- Unleashing the Tiger: Inference Attacks on Split LearningDario Pasquini, Giuseppe Ateniese, Massimo BernaschiCCS 2021 · 被引用 14 次
- Passive Inference Attacks on Split Learning via Adversarial RegularizationXiaochen Zhu, Xinjian Luo, Yuncheng Wu, Yangfan Jiang 等NDSS 2025
- Chronic Poisoning: Backdoor Attack against Split LearningFangchao Yu, Bo Zeng, Kai Zhao, Zhi Pang 等AAAI 2024 · 被引用 15 次
- Unveiling the Vulnerability of Private Fine-Tuning in Split-Based Frameworks for Large Language Models: A Bidirectionally Enhanced AttackGuanzhong Chen, Zhenghan Qin, Mingxin Yang, Yajie Zhou 等CCS 2024 · 被引用 7 次
