Focusing on Pinocchio's Nose: A Gradients Scrutinizer to Thwart Split-Learning Hijacking Attacks Using Intrinsic Attributes
Jiayun Fu, Xiaojing Ma, Bin B. Zhu, Pingyi Hu, Ruixin Zhao, Yaru Jia, Peng Xu, Hai Jin, Dongmei Zhang
摘要
—Split learning is privacy-preserving distributed learning that has gained momentum recently. It also faces new security challenges. FSHA [37] is a serious threat to split learning. In FSHA, a malicious server hijacks training to trick clients to train the encoder of an autoencoder instead of a classification model. Intermediate results sent to the server by a client are actually latent codes of private training samples, which can be reconstructed with high fidelity from the received codes with the decoder of the autoencoder. SplitGuard [10] is the only existing effective defense against hijacking attacks. It is an active method that injects falsely labeled data to incur abnormal behaviors to detect hijacking attacks. Such injection also incurs an adverse impact on honest training of intended models. In this paper, we first show that SplitGuard is vulnerable to an adaptive hijacking attack named SplitSpy. SplitSpy exploits the same property that SplitGuard exploits to detect hijacking attacks. In SplitSpy, a malicious server maintains a shadow model that performs the intended task to detect falsely labeled data and evade SplitGuard. Our experimental evaluation indicates that SplitSpy can effectively evade SplitGuard. Then we propose a novel passive detection method, named Gradients Scrutinizer, which relies on intrinsic differences between gradients from an intended model and those from a malicious model: the expected similarity among gradients of same-label samples differs from the expected similarity among gradients of different-label samples for an intended model, while they are the same for a malicious model. This intrinsic distinguishability
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Chronic Poisoning: Backdoor Attack against Split LearningFangchao Yu, Bo Zeng, Kai Zhao, Zhi Pang 等AAAI 2024 · 被引用 15 次
- A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningXiaoyang Xu, Mengda Yang, Wenzhe Yi, Ziang Li 等CVPR 2024 · 被引用 13 次
- SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split LearningPhillip Rieger, Alessandro Pegoraro, Kavita Kumari, Tigist Abera 等NDSS 2025
- URVFL: Undetectable Data Reconstruction Attack on Vertical Federated LearningDuanyi Yao, Songze Li, Xueluan Gong, Sizai Hou 等NDSS 2025
- Passive Inference Attacks on Split Learning via Adversarial RegularizationXiaochen Zhu, Xinjian Luo, Yuncheng Wu, Yangfan Jiang 等NDSS 2025
它引用的顶会 Paper5
- SplitFed: When Federated Learning Meets Split LearningChandra Thapa, Mahawaga Arachchige Pathum Chamikara, Seyit Camtepe, Lichao SunAAAI 2022 · 被引用 863 次
- Group Knowledge Transfer: Federated Learning of Large CNNs at the EdgeChaoyang He, Murali Annavaram, Salman AvestimehrNeurIPS 2020 · 被引用 605 次
- Deep Learning with Label Differential PrivacyBadih Ghazi, Noah Golowich, Ravi Kumar, Pasin Manurangsi 等NeurIPS 2021 · 被引用 193 次
- Label Leakage and Protection in Two-party Split LearningOscar Li, Jiankai Sun, Xin Yang, Weihao Gao 等ICLR 2022 · 被引用 170 次
- Unleashing the Tiger: Inference Attacks on Split LearningDario Pasquini, Giuseppe Ateniese, Massimo BernaschiCCS 2021 · 被引用 14 次
相关 Paper
- SecureSplit: Mitigating Backdoor Attacks in Split LearningZhihao Dou, Dongfei Cui, Weida Wang, Anjun Gao 等WWW 2026 · 被引用 1 次
- HealSplit: Towards Self-Healing Through Adversarial Distillation in Split Federated LearningYuhan Xie, Chen LyuAAAI 2026
- ZORRO: Zero-Knowledge Robustness and Privacy for Split LearningNojan Sheybani, Alessandro Pegoraro, Jonathan Knauer, Phillip Rieger 等CCS 2025
- PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client AttackXinben Gao, Lan ZhangUSENIX Security 2023
- DualGuard: A Parameter Space Transformation Approach for Bidirectional Defense in Split-Based LLM Fine-TuningZihan Liu, Yizhen Wang, Rui Wang, Sai WuACL 2025
