An Accuracy-Lossless Perturbation Method for Defending Privacy Attacks in Federated Learning
Xue Yang, Yan Feng, Weijun Fang, Jun Shao, Xiaohu Tang, Shu-Tao Xia, Rongxing Lu
摘要
Although federated learning improves privacy of training data by exchanging local gradients or parameters rather than raw data, the adversary still can leverage local gradients and parameters to obtain local training data by launching reconstruction and membership inference attacks. To defend such privacy attacks, many noises perturbation methods (like differential privacy or CountSketch matrix) have been widely designed. However, the strong defence ability and high learning accuracy of these schemes cannot be ensured at the same time, which will impede the wide application of FL in practice (especially for medical or financial institutions that require both high accuracy and strong privacy guarantee). To overcome this issue, in this paper, we propose an efficient model perturbation method for federated learning to defend reconstruction and membership inference attacks launched by curious clients. On the one hand, similar to the differential privacy, our method also selects random numbers as perturbed noises added to the global model parameters, and thus it is very efficient and easy to be integrated in practice. Meanwhile, the random selected noises are positive real numbers and the corresponding value can be arbitrarily large, and thus the strong defence ability can be ensured. On the other hand, unlike differential privacy or other perturbation methods that cannot eliminate the added noises, our method allows the server to recover the true gradients by eliminating the added noises. Therefore, our method does not hinder learning accuracy at all. Extensive experiments demonstrate that for both regression and classification tasks, our method achieves the same accuracy as non-private approaches and outperforms the state-ofthe-art related schemes. Besides, the defence ability of our method is significantly better than the state-of-the-art related defence schemes. Specifically, for the membership inference attack, our method achieves attack success rate (ASR) of around 50%, which is equivalent to blind guessing. However, the ASR of other defence methods is around 60%, which means that clients have a certain advantage to attack successfully compared with blind guessing. For the reconstruction attack, the ASR of our method is around X. Yang, Y. Feng, W. Fang and S. Xia are with
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- BlockDFL: A Blockchain-based Fully Decentralized Peer-to-Peer Federated Learning FrameworkZhen Qin, Xueqiang Yan, Mengchu Zhou, Shuiguang DengWWW 2024 · 被引用 39 次
- Traceable Federated Continual LearningQiang Wang, Bingyan Liu, Yawen LiCVPR 2024 · 被引用 16 次
- United We Defend: Collaborative Membership Inference Defenses in Federated LearningLi Bai, Junxu Liu, Sen Zhang, Xinwei Zhang 等USENIX Security 2026
它引用的顶会 Paper7
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang 等ICLR 2020 · 被引用 2,930 次
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 被引用 1,778 次
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 被引用 1,581 次
- BatchCrypt: Efficient Homomorphic Encryption for Cross-Silo Federated LearningChengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang 等USENIX ATC 2020 · 被引用 967 次
相关 Paper
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang 等CVPR 2021
- From Risk to Resilience: Towards Assessing and Mitigating the Risk of Data Reconstruction Attacks in Federated LearningXiangrui Xu, Zhize Li, Yufei Han, Bin Wang 等USENIX Security 2025
- Enhancing Privacy Preservation in Federated Learning via Learning Rate PerturbationGuangnian Wan, Haitao Du, Xuejing Yuan, Jun Yang 等ICCV 2023 · 被引用 2 次
- Defending Against Data Reconstruction Attacks in Federated Learning: An Information Theory ApproachQi Tan, Qi Li, Yi Zhao, Zhuotao Liu 等USENIX Security 2024 · 被引用 10 次
- Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated LearningWenjin Mo, Zhiyuan Li, Minghong Fang, Mingwei FangICCV 2025 · 被引用 3 次
