PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client Attack
Xinben Gao, Lan Zhang
摘要
Split learning (SL) is a popular framework to protect a client's training data by splitting up a model among the client and the server. Previous efforts have shown that a semi-honest server can conduct a model inversion attack to recover the client's inputs and model parameters to some extent, as well as to infer the labels. However, those attacks require the knowledge of the client network structure and the performance deteriorates dramatically as the client network gets deeper (≥ 2 layers). In this work, we explore the attack on SL in a more general and challenging situation where the client model is unknown to the server and gets more complex and deeper. Different from the conventional model inversion, we investigate the inherent privacy leakage through the server model in SL and reveal that clients' functionality and private data can be easily stolen by the server model, and a series of intermediate server models during SL can even cause more leakage. Based on the insights, we propose a new attack on SL: Pseudo-Client ATtack (PCAT). To the best of our knowledge, this is the first attack for a semi-honest server to steal clients' functionality, reconstruct private inputs and infer private labels without any knowledge about the clients' model. The only requirement for the server is a tiny dataset (about 0.1% -5% of the private training set) for the same learning task. What's more, the attack is transparent to clients, so a server can obtain clients' privacy without taking any risk of being detected by the client. We implement PCAT on various benchmark datasets and models. Extensive experiments testify that our attack significantly outperforms the state-of-the-art attack in various conditions, including more complex models and learning tasks, even in non-i.i.d. conditions. Moreover, our functionality stealing attack is resilient to the existing defensive mechanism.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Chronic Poisoning: Backdoor Attack against Split LearningFangchao Yu, Bo Zeng, Kai Zhao, Zhi Pang 等AAAI 2024 · 被引用 15 次
- A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningXiaoyang Xu, Mengda Yang, Wenzhe Yi, Ziang Li 等CVPR 2024 · 被引用 13 次
- Split UnlearningYanna Jiang, Guangsheng Yu, Qin Wang, Xu Wang 等CCS 2025 · 被引用 1 次
- SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split LearningPhillip Rieger, Alessandro Pegoraro, Kavita Kumari, Tigist Abera 等NDSS 2025
- Split Adaptation for Pre-trained Vision TransformersLixu Wang, Bingqi Shang, Yi Li, Payal Mohapatra 等CVPR 2025
它引用的顶会 Paper9
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter 等USENIX Security 2016 · 被引用 2,088 次
- Stealing Hyperparameters in Machine LearningBinghui Wang, Neil Zhenqiang GongS&P 2018 · 被引用 504 次
- AttriGuard: A Practical Defense Against Attribute Inference Attacks via Adversarial Machine LearningJinyuan Jia, Neil Zhenqiang GongUSENIX Security 2018 · 被引用 194 次
- Label Leakage and Protection in Two-party Split LearningOscar Li, Jiankai Sun, Xin Yang, Weihao Gao 等ICLR 2022 · 被引用 170 次
相关 Paper
- Unleashing the Tiger: Inference Attacks on Split LearningDario Pasquini, Giuseppe Ateniese, Massimo BernaschiCCS 2021 · 被引用 14 次
- Passive Inference Attacks on Split Learning via Adversarial RegularizationXiaochen Zhu, Xinjian Luo, Yuncheng Wu, Yangfan Jiang 等NDSS 2025
- ResSFL: A Resistance Transfer Framework for Defending Model Inversion Attack in Split Federated LearningJingtao Li, Adnan Siraj Rakin, Xing Chen, Zhezhi He 等CVPR 2022 · 被引用 70 次
- InfoDecom: Decomposing Information for Defending Against Privacy Leakage in Split InferenceRuijun Deng, Zhihui Lu, Qiang DuanAAAI 2026
- Mitigating Membership Inference Attacks by Self-Distillation Through a Novel Ensemble ArchitectureXinyu Tang, Saeed Mahloujifar, Liwei Song, Virat Shejwalkar 等USENIX Security 2022
