Poisoning-Assisted Property Inference Attack Against Federated Learning

推论 计算机科学 财产(哲学) 判别式 对手 计算机安全 机器学习 人工智能 哲学 认识论
作者
Zhibo Wang,Yuting Huang,Mengkai Song,Libing Wu,Xue Feng,Kui Ren
出处
期刊:IEEE Transactions on Dependable and Secure Computing [Institute of Electrical and Electronics Engineers]
卷期号:20 (4): 3328-3340 被引量:20
标识
DOI:10.1109/tdsc.2022.3196646
摘要

Federated learning (FL) has emerged as an ideal privacy-preserving learning technique which can train a global model in a collaborative way while preserving the private data in the local. However, recent advances have demonstrated that FL is still vulnerable to inference attacks, such as reconstruction attack and membership inference. Among these attacks, the property inference attack, aiming to infer properties of the training data that are irrelevant with the learning objective, has not received too much attention while resulting in severe privacy leakage. Existing property inference attack approaches either cannot achieve satisfactory performance when the global model has converged or under dynamic FL where participants can drop in and drop out freely. In this paper, we propose a novel poisoning-assisted property inference attack (PAPI-attack) against FL. The key insight is that there exists underlying discriminative ability in the periodic model updates, which reflects the change of the data distribution, especially the occurrence of the sensitive property. Thus, a binary attack model can be constructed by a malicious participant for inferring the unintended information. More importantly, we present a property-specific poisoning mechanism by modifying the label of training data from the adversary to distort the decision boundary of shared (global) model in FL. Consequently, benign participants are induced to disclose more information about the sensitive property. Extensive experiments on real-world datasets demonstrate that PAPI-attack outperforms the state-of-the-art property inference attacks against FL.

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
喵星小天才完成签到,获得积分10
3秒前
凝聚态阿隅完成签到 ,获得积分10
3秒前
3秒前
小犬完成签到,获得积分10
5秒前
哈哈发布了新的文献求助10
5秒前
小菜一碟2021完成签到,获得积分10
6秒前
7秒前
7秒前
星宇完成签到 ,获得积分10
7秒前
9秒前
高贵路灯发布了新的文献求助10
10秒前
打打应助张钰婷啦啦啦采纳,获得10
14秒前
嘀嘀发布了新的文献求助10
14秒前
15秒前
鳗鱼海安发布了新的文献求助10
16秒前
16秒前
Ramer556完成签到,获得积分10
16秒前
17秒前
Akim应助东方一斩采纳,获得10
17秒前
qiandi完成签到,获得积分10
19秒前
Ehgnix发布了新的文献求助10
19秒前
小二郎应助hello_25baby采纳,获得10
20秒前
21秒前
21秒前
小蘑菇应助雍傲易采纳,获得20
21秒前
ENIX发布了新的文献求助10
21秒前
21秒前
23秒前
王艺霏发布了新的文献求助10
24秒前
wqm完成签到,获得积分10
24秒前
研友_8Y26PL发布了新的文献求助10
26秒前
穆振家发布了新的文献求助10
26秒前
28秒前
29秒前
32秒前
晨晨CC发布了新的文献求助10
32秒前
研友_Z6Qrbn发布了新的文献求助10
33秒前
hello_25baby发布了新的文献求助10
34秒前
34秒前
高分求助中
LNG地下式貯槽指針(JGA指-107) 1000
LNG地上式貯槽指針 (JGA指 ; 108) 1000
Preparation and Characterization of Five Amino-Modified Hyper-Crosslinked Polymers and Performance Evaluation for Aged Transformer Oil Reclamation 700
Operative Techniques in Pediatric Orthopaedic Surgery 510
How Stories Change Us A Developmental Science of Stories from Fiction and Real Life 500
九经直音韵母研究 500
Full waveform acoustic data processing 500
热门求助领域 (近24小时)
化学 医学 材料科学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 免疫学 细胞生物学 电极
热门帖子
关注 科研通微信公众号,转发送积分 2929877
求助须知:如何正确求助?哪些是违规求助? 2581287
关于积分的说明 6961571
捐赠科研通 2230090
什么是DOI,文献DOI怎么找? 1184889
版权声明 589565
科研通“疑难数据库(出版商)”最低求助积分说明 579942