Defending Batch-Level Label Inference and Replacement Attacks in Vertical Federated Learning

被引:17
作者
Zou, Tianyuan [1 ]
Liu, Yang [2 ]
Kang, Yan [3 ]
Liu, Wenhan [4 ]
He, Yuanqin [3 ]
Yi, Zhihao [3 ]
Yang, Qiang [5 ]
Zhang, Ya-Qin [2 ]
机构
[1] Tsinghua Univ, Comp Sci & Technol, Beijing 100084, Peoples R China
[2] Tsinghua Univ, Inst AI Ind Res AIR, Beijing 100084, Peoples R China
[3] Webank, Shenzhen 518052, Peoples R China
[4] Shandong Univ, Weihai 264209, Peoples R China
[5] Hong Kong Univ Sci & Technol, Dept Comp Sci & Engn, Kowloon, Hong Kong, Peoples R China
关键词
Task analysis; Training; Protocols; Collaborative work; Data models; Homomorphic encryption; Differential privacy; Vertical federated learning; label inference; label replacement; confusional autoencoder; privacy;
D O I
10.1109/TBDATA.2022.3192121
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In a vertical federated learning (VFL) scenario where features and models are split into different parties, it has been shown that sample-level gradient information can be exploited to deduce crucial label information that should be kept secret. An immediate defense strategy is to protect sample-level messages communicated with Homomorphic Encryption (HE), exposing only batch-averaged local gradients to each party. In this paper, we show that even with HE-protected communication, private labels can still be reconstructed with high accuracy by gradient inversion attack, contrary to the common belief that batch-averaged information is safe to share under encryption. We then show that backdoor attack can also be conducted by directly replacing encrypted communicated messages without decryption. To tackle these attacks, we propose a novel defense method, Confusional AutoEncoder (termed CAE), which is based on autoencoder and entropy regularization to disguise true labels. To further defend attackers with sufficient prior label knowledge, we introduce DiscreteSGD-enhanced CAE (termed DCAE), and show that DCAE significantly boosts the main task accuracy than other known methods when defending various label inference attacks.
引用
收藏
页码:1016 / 1027
页数:12
相关论文
共 50 条
[31]   Universal adversarial backdoor attacks to fool vertical federated learning [J].
Chen, Peng ;
Du, Xin ;
Lu, Zhihui ;
Chai, Hongfeng .
COMPUTERS & SECURITY, 2024, 137
[32]   Preventing Strategic Behaviors in Collaborative Inference for Vertical Federated Learning [J].
Xing, Yidan ;
Zheng, Zhenzhe ;
Wu, Fan .
PROCEEDINGS OF THE 30TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2024, 2024, :3574-3585
[33]   Feature Inference Attack on Model Predictions in Vertical Federated Learning [J].
Luo, Xinjian ;
Wu, Yuncheng ;
Xiao, Xiaokui ;
Ooi, Beng Chin .
2021 IEEE 37TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2021), 2021, :181-192
[34]   Defending against membership inference attacks: RM Learning is all you need [J].
Zhang, Zheng ;
Ma, Jianfeng ;
Ma, Xindi ;
Yang, Ruikang ;
Wang, Xiangyu ;
Zhang, Junying .
INFORMATION SCIENCES, 2024, 670
[35]   FL-TIA: Novel Time Inference Attacks on Federated Learning [J].
Sandeepa, Chamara ;
Siniarski, Bartlomiej ;
Wang, Shen ;
Liyanage, Madhusanka .
2023 IEEE 22ND INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, BIGDATASE, CSE, EUC, ISCI 2023, 2024, :173-180
[36]   Evaluating Differential Privacy in Federated Learning based on Membership Inference Attacks [J].
He, Peng ;
Wang, Xinyu ;
Zhang, Weijiao ;
Wang, Zhongkai ;
Wang, Song ;
Ou, Chuangxin ;
Li, Guozheng .
2024 10TH INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING AND COMMUNICATIONS, BIGCOM, 2024, :196-203
[37]   Shielding Federated Learning Systems against Inference Attacks with ARM TrustZone [J].
Messaoud, Aghiles Ait ;
Ben Mokhtar, Sonia ;
Nitu, Vlad ;
Schiavoni, Valerio .
PROCEEDINGS OF THE TWENTY-THIRD ACM/IFIP INTERNATIONAL MIDDLEWARE CONFERENCE, MIDDLEWARE 2022, 2022, :335-348
[38]   Detection of False Data Injection Attacks in Distribution Networks: A Vertical Federated Learning Approach [J].
Kesici, Mert ;
Pal, Bikash ;
Yang, Guangya .
IEEE TRANSACTIONS ON SMART GRID, 2024, 15 (06) :5952-5964
[39]   BadCleaner: Defending Backdoor Attacks in Federated Learning via Attention-Based Multi-Teacher Distillation [J].
Zhang, Jiale ;
Zhu, Chengcheng ;
Ge, Chunpeng ;
Ma, Chuan ;
Zhao, Yanchao ;
Sun, Xiaobing ;
Chen, Bing .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) :4559-4573
[40]   Improving Availability of Vertical Federated Learning: Relaxing Inference on Non-overlapping Data [J].
Ren, Zhenghang ;
Yang, Liu ;
Chen, Kai .
ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2022, 13 (04)