Defending Batch-Level Label Inference and Replacement Attacks in Vertical Federated Learning

被引:11
|
作者
Zou, Tianyuan [1 ]
Liu, Yang [2 ]
Kang, Yan [3 ]
Liu, Wenhan [4 ]
He, Yuanqin [3 ]
Yi, Zhihao [3 ]
Yang, Qiang [5 ]
Zhang, Ya-Qin [2 ]
机构
[1] Tsinghua Univ, Comp Sci & Technol, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Inst AI Ind Res AIR, Beijing 100084, Peoples R China
[3] Webank, Shenzhen 518052, Peoples R China
[4] Shandong Univ, Weihai 264209, Peoples R China
[5] Hong Kong Univ Sci & Technol, Dept Comp Sci & Engn, Kowloon, Hong Kong, Peoples R China
关键词
Task analysis; Training; Protocols; Collaborative work; Data models; Homomorphic encryption; Differential privacy; Vertical federated learning; label inference; label replacement; confusional autoencoder; privacy;
D O I
10.1109/TBDATA.2022.3192121
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In a vertical federated learning (VFL) scenario where features and models are split into different parties, it has been shown that sample-level gradient information can be exploited to deduce crucial label information that should be kept secret. An immediate defense strategy is to protect sample-level messages communicated with Homomorphic Encryption (HE), exposing only batch-averaged local gradients to each party. In this paper, we show that even with HE-protected communication, private labels can still be reconstructed with high accuracy by gradient inversion attack, contrary to the common belief that batch-averaged information is safe to share under encryption. We then show that backdoor attack can also be conducted by directly replacing encrypted communicated messages without decryption. To tackle these attacks, we propose a novel defense method, Confusional AutoEncoder (termed CAE), which is based on autoencoder and entropy regularization to disguise true labels. To further defend attackers with sufficient prior label knowledge, we introduce DiscreteSGD-enhanced CAE (termed DCAE), and show that DCAE significantly boosts the main task accuracy than other known methods when defending various label inference attacks.
引用
收藏
页码:1016 / 1027
页数:12
相关论文
共 45 条
  • [1] A defense mechanism against label inference attacks in Vertical Federated Learning
    Arazzi, Marco
    Nicolazzo, Serena
    Nocera, Antonino
    NEUROCOMPUTING, 2025, 624
  • [2] Beyond model splitting: Preventing label inference attacks in vertical federated learning with dispersed training
    Wang, Yilei
    Lv, Qingzhe
    Zhang, Huang
    Zhao, Minghao
    Sun, Yuhong
    Ran, Lingkai
    Li, Tao
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2023, 26 (05): : 2691 - 2707
  • [3] HashVFL: Defending Against Data Reconstruction Attacks in Vertical Federated Learning
    Qiu, Pengyu
    Zhang, Xuhong
    Ji, Shouling
    Fu, Chong
    Yang, Xing
    Wang, Ting
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3435 - 3450
  • [4] Defending Against Data and Model Backdoor Attacks in Federated Learning
    Wang, Hao
    Mu, Xuejiao
    Wang, Dong
    Xu, Qiang
    Li, Kaiju
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (24): : 39276 - 39294
  • [5] DPFLA: Defending Private Federated Learning Against Poisoning Attacks
    Feng, Xia
    Cheng, Wenhao
    Cao, Chunjie
    Wang, Liangmin
    Sheng, Victor S.
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2024, 17 (04) : 1480 - 1491
  • [6] Beyond model splitting: Preventing label inference attacks in vertical federated learning with dispersed training
    Yilei Wang
    Qingzhe Lv
    Huang Zhang
    Minghao Zhao
    Yuhong Sun
    Lingkai Ran
    Tao Li
    World Wide Web, 2023, 26 : 2691 - 2707
  • [7] Source Inference Attacks: Beyond Membership Inference Attacks in Federated Learning
    Hu, Hongsheng
    Zhang, Xuyun
    Salcic, Zoran
    Sun, Lichao
    Choo, Kim-Kwang Raymond
    Dobbie, Gillian
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3012 - 3029
  • [8] ProjPert: Projection-Based Perturbation for Label Protection in Split Learning Based Vertical Federated Learning
    Fu, Fangcheng
    Wang, Xuanyu
    Jiang, Jiawei
    Xue, Huanran
    Cui, Bui
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (07) : 3417 - 3428
  • [9] OQFL: An Optimized Quantum-Based Federated Learning Framework for Defending Against Adversarial Attacks in Intelligent Transportation Systems
    Yamany, Waleed
    Moustafa, Nour
    Turnbull, Benjamin
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2023, 24 (01) : 893 - 903
  • [10] Defending Against Membership Inference Attack for Counterfactual Federated Recommendation With Differentially Private Representation Learning
    Liu, Xiuwen
    Chen, Yanjiao
    Pang, Shanchen
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 8037 - 8051