FedMIA: An Effective Membership Inference Attack Exploiting "All for One" Principle in Federated Learning
Gongxi Zhu, Donghao Li, Hanlin Gu, Yuan Yao, Lixin Fan, Yuxing Han
摘要
Federated Learning (FL) is a promising approach for training machine learning models on decentralized data while preserving privacy. However, privacy risks, particularly Membership Inference Attacks (MIAs), which aim to determine whether a specific data point belongs to a target client's training set, remain a significant concern. Existing methods for implementing MIAs in FL primarily analyze updates from the target client, focusing on metrics such as loss, gradient norm, and gradient difference. However, these methods fail to leverage updates from non-target clients, potentially underutilizing available information. In this paper, we first formulate a one-tailed likelihood-ratio hypothesis test based on the likelihood of updates from nontarget clients. Building upon this formulation, we introduce a three-step Membership Inference Attack (MIA) method, called FedMIA, which follows the "all for one"-leveraging updates from all clients across multiple communication rounds to enhance MIA effectiveness. Both theoretical analysis and extensive experimental results demonstrate that FedMIA outperforms existing MIAs in both classification and generative tasks. Additionally, it can be integrated as an extension to existing methods and is robust against various defense strategies, Non-IID data, and different federated structures. Our code is available in https:// github.com/Liar-Mask/FedMIA .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual ApproachGuilin Deng, Silong Chen, Yuchuan Luo, Yi Liu 等S&P 2026 · 被引用 4 次
- FLARE: A Wireless Side-Channel Fingerprinting Attack on Federated LearningMd Nahid Hasan Shuvo, Moinul Hossain, Anik Mallik, Jeffrey N. Twigg 等INFOCOM 2026 · 被引用 1 次
- United We Defend: Collaborative Membership Inference Defenses in Federated LearningLi Bai, Junxu Liu, Sen Zhang, Xinwei Zhang 等USENIX Security 2026
- FedSDA: Federated Stain Distribution Alignment for Non-IID Histopathological Image ClassificationCheng-Chang Tsai, Kai-Wen Cheng, Chun-Shien LuAAAI 2026
它引用的顶会 Paper14
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 被引用 1,822 次
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 被引用 1,778 次
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang 等NDSS 2019 · 被引用 1,141 次
相关 Paper
- A Unified Defense Framework Against Membership Inference in Federated Learning via Distillation and Contribution-Aware AggregationLiwei Zhang, Linghui Li, Xiaotian Si, Ziduo Guo 等NDSS 2026 · 被引用 1 次
- Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated LearningWenjin Mo, Zhiyuan Li, Minghong Fang, Mingwei FangICCV 2025 · 被引用 3 次
- Efficient Privacy Auditing in Federated LearningHongyan Chang, Brandon Edwards, Anindya S. Paul, Reza ShokriUSENIX Security 2024 · 被引用 9 次
- The Hidden Risk: Membership Inference Attacks on Multimodal Federated Learning via Modality ImbalanceChang Ma, Jun Li, Kang Wei, Yipeng Zhou 等ICML 2026
- How Does Data Augmentation Affect Privacy in Machine Learning?Da Yu, Huishuai Zhang, Wei Chen, Jian Yin 等AAAI 2021 · 被引用 67 次
