Gradient Disaggregation: Breaking Privacy in Federated Learning by Reconstructing the User Participant Matrix
Maximilian Lam, Gu-Yeon Wei, David Brooks, Vijay Janapa Reddi, Michael Mitzenmacher
摘要
We show that aggregated model updates in federated learning may be insecure. An untrusted central server may disaggregate user updates from sums of updates across participants given repeated observations, enabling the server to recover privileged information about individual users' private training data via traditional gradient inference attacks. Our method revolves around reconstructing participant information (e.g: which rounds of training users participated in) from aggregated model updates by leveraging summary information from device analytics commonly used to monitor, debug, and manage federated learning systems. Our attack is parallelizable and we successfully disaggregate user updates on settings with up to thousands of participants. We quantitatively and qualitatively demonstrate significant improvements in the capability of various inference attacks on the disaggregated updates. Our attack enables the attribution of learned properties to individual users, violating anonymity, and shows that a determined central server may undermine the secure aggregation protocol to break individual users' data privacy in federated learning.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Fishing for User Data in Large-Batch Federated Learning via Gradient MagnificationYuxin Wen, Jonas Geiping, Liam Fowl, Micah Goldblum 等ICML 2022 · 被引用 119 次
- Eluding Secure Aggregation in Federated Learning via Model InconsistencyDario Pasquini, Danilo Francati, Giuseppe AtenieseCCS 2022 · 被引用 92 次
- SecretFlow-SPU: A Performant and User-Friendly Framework for Privacy-Preserving Machine LearningJunming Ma, Yancheng Zheng, Jun Feng, Derun Zhao 等USENIX ATC 2023 · 被引用 73 次
- Personalized Federated Learning under Mixture of DistributionsYue Wu, Shuaicheng Zhang, Wenchao Yu, Yanchi Liu 等ICML 2023 · 被引用 71 次
- Loki: Large-scale Data Reconstruction Attack against Federated Learning through Model ManipulationJoshua C. Zhao, Atul Sharma, Ahmed Roushdy Elkordy, Yahya H. Ezzeldin 等S&P 2024 · 被引用 64 次
它引用的顶会 Paper6
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone 等CCS 2017 · 被引用 3,936 次
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 被引用 1,822 次
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 被引用 1,736 次
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 被引用 1,581 次
相关 Paper
- Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified ModelsLiam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum 等ICLR 2022 · 被引用 181 次
- Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated LearningZhibo Wang, Zhiwei Chang, Jiahui Hu, Xiaoyi Pang 等INFOCOM 2024 · 被引用 10 次
- Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language ModelsLiam H. Fowl, Jonas Geiping, Steven Reich, Yuxin Wen 等ICLR 2023 · 被引用 10 次
- Scale-MIA: A Scalable Model Inversion Attack against Secure Federated Learning via Latent Space ReconstructionShanghao Shi, Ning Wang, Yang Xiao, Chaoyu Zhang 等NDSS 2025
- The Resource Problem of Using Linear Layer Leakage Attack in Federated LearningJoshua C. Zhao, Ahmed Roushdy Elkordy, Atul Sharma, Yahya H. Ezzeldin 等CVPR 2023
