FedInverse: Evaluating Privacy Leakage in Federated Learning
Di Wu, Jun Bai, Yiliao Song, Junjun Chen, Wei Zhou, Yong Xiang, Atul Sajjanhar
摘要
Federated Learning (FL) is a distributed machine learning technique where multiple devices (such as smartphones or IoT devices) train a shared global model by using their local data. FL promises better data privacy as the individual data isn't shared with servers or other participants. However, this research uncovers a groundbreaking insight: a model inversion (MI) attacker, who acts as a benign participant, can invert the shared global model and obtain the data belonging to other participants. In such scenarios, distinguishing between attackers and benign participants becomes challenging, leading to severe data-leakage risk in FL. In addition, we found even the most advanced defense approaches could not effectively address this issue. Therefore, it is important to evaluate such data-leakage risks of an FL system before using it. Motivated by that, we propose FedInverse to evaluate whether the FL global model can be inverted by MI attackers. In particular, FedInverse can be optimized by leveraging the Hilbert-Schmidt independence criterion (HSIC) as a regularizer to adjust the diversity of the MI attack generator. We test FedInverse with three typical MI attackers, GMI, KED-MI, and VMI. The experiments show that FedInverse can effectively evaluate the data leakage risk that attackers successfully obtain the data belonging to other participants. The code of this work is available at https://github.com/Jun-B0518/FedInverse
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- A Unified Solution to Diverse Heterogeneities in One-Shot Federated LearningJun Bai, Yiliao Song, Di Wu, Atul Sajjanhar 等KDD 2025
- Legal Judgment Prediction: A Reflection on the State of the ArtYi Feng, Chuanyi Li, Vincent NgACL 2026
它引用的顶会 Paper11
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 被引用 1,822 次
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 被引用 1,581 次
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li 等NeurIPS 2021 · 被引用 419 次
- Variational Model Inversion AttacksKuan-Chieh Wang, Yan Fu, Ke Li, Ashish Khisti 等NeurIPS 2021 · 被引用 142 次
相关 Paper
- FedInv: Byzantine-Robust Federated Learning by Inversing Local Model UpdatesBo Zhao, Peng Sun, Tao Wang, Keyu JiangAAAI 2022 · 被引用 82 次
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang 等CVPR 2021
- Enhancing Privacy Preservation in Federated Learning via Learning Rate PerturbationGuangnian Wan, Haitao Du, Xuejing Yuan, Jun Yang 等ICCV 2023 · 被引用 2 次
- Surrogate Model Extension (SME): A Fast and Accurate Weight Update Attack on Federated LearningJunyi Zhu, Ruicong Yao, Matthew B. BlaschkoICML 2023 · 被引用 17 次
- FLShield: A Validation Based Federated Learning Framework to Defend Against Poisoning AttacksEhsanul Kabir, Zeyu Song, Md. Rafi Ur Rashid, Shagufta MehnazS&P 2024 · 被引用 32 次
