Eluding Secure Aggregation in Federated Learning via Model Inconsistency
Dario Pasquini, Danilo Francati, Giuseppe Ateniese
摘要
Secure aggregation is a cryptographic protocol that securely computes the aggregation of its inputs. It is pivotal in keeping model updates private in federated learning. Indeed, the use of secure aggregation prevents the server from learning the value and the source of the individual model updates provided by the users, hampering inference and data attribution attacks. In this work, we show that a malicious server can easily elude secure aggregation as if the latter were not in place. We devise two different attacks capable of inferring information on individual private training datasets, independently of the number of users participating in the secure aggregation. This makes them concrete threats in large-scale, real-world federated learning applications. The attacks are generic and equally effective regardless of the secure aggregation protocol used. They exploit a vulnerability of the federated learning protocol caused by incorrect usage of secure aggregation and lack of parameter validation. Our work demonstrates that current implementations of federated learning with secure aggregation offer only a "false sense of security".
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper33
- Loki: Large-scale Data Reconstruction Attack against Federated Learning through Model ManipulationJoshua C. Zhao, Atul Sharma, Ahmed Roushdy Elkordy, Yahya H. Ezzeldin 等S&P 2024 · 被引用 64 次
- Byzantine-Robust Decentralized Federated LearningMinghong Fang, Zifan Zhang, Hairi, Prashant Khanduri 等CCS 2024 · 被引用 38 次
- FedInverse: Evaluating Privacy Leakage in Federated LearningDi Wu, Jun Bai, Yiliao Song, Junjun Chen 等ICLR 2024 · 被引用 22 次
- Hiding in Plain Sight: Disguising Data Stealing Attacks in Federated LearningKostadin Garov, Dimitar Iliev Dimitrov, Nikola Jovanovic, Martin T. VechevICLR 2024 · 被引用 13 次
- Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated LearningZhibo Wang, Zhiwei Chang, Jiahui Hu, Xiaoyi Pang 等INFOCOM 2024 · 被引用 10 次
它引用的顶会 Paper22
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah 等NeurIPS 2020 · 被引用 64,255 次
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone 等CCS 2017 · 被引用 3,936 次
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 被引用 1,822 次
相关 Paper
- Gradient Disaggregation: Breaking Privacy in Federated Learning by Reconstructing the User Participant MatrixMaximilian Lam, Gu-Yeon Wei, David Brooks, Vijay Janapa Reddi 等ICML 2021 · 被引用 78 次
- ELSA: Secure Aggregation for Federated Learning with Malicious ActorsMayank Rathee, Conghao Shen, Sameer Wagh, Raluca Ada PopaS&P 2023
- The Resource Problem of Using Linear Layer Leakage Attack in Federated LearningJoshua C. Zhao, Ahmed Roushdy Elkordy, Atul Sharma, Yahya H. Ezzeldin 等CVPR 2023
- Scale-MIA: A Scalable Model Inversion Attack against Secure Federated Learning via Latent Space ReconstructionShanghao Shi, Ning Wang, Yang Xiao, Chaoyu Zhang 等NDSS 2025
- RoFL: Robustness of Secure Federated LearningHidde Lycklama, Lukas Burkhalter, Alexander Viand, Nicolas Küchler 等S&P 2023
