Secure Aggregation Is Not Private Against Membership Inference Attacks

被引:1
作者
Ngo, Khac-Hoang [1 ]
Ostman, Johan [2 ]
Durisi, Giuseppe [1 ]
Graell i Amat, Alexandre [1 ]
机构
[1] Chalmers Univ Technol, Dept Elect Engn, Gothenburg, Sweden
[2] AI Sweden, Gothenburg, Sweden
来源
MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES-RESEARCH TRACK, PT VI, ECML PKDD 2024 | 2024年 / 14946卷
基金
瑞典研究理事会;
关键词
Federated learning; Secure aggregation; Differential privacy; Membership inference;
D O I
10.1007/978-3-031-70365-2_11
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Secure aggregation (SecAgg) is a commonly-used privacy-enhancing mechanism in federated learning, affording the server access only to the aggregate of model updates while safeguarding the confidentiality of individual updates. Despite widespread claims regarding SecAgg's privacy-preserving capabilities, a formal analysis of its privacy is lacking, making such presumptions unjustified. In this paper, we delve into the privacy implications of SecAgg by treating it as a local differential privacy (LDP) mechanism for each local update. We design a simple attack wherein an adversarial server seeks to discern which update vector a client submitted, out of two possible ones, in a single training round of federated learning under SecAgg. By conducting privacy auditing, we assess the success probability of this attack and quantify the LDP guarantees provided by SecAgg. Our numerical results unveil that, contrary to prevailing claims, SecAgg offers weak privacy against membership inference attacks even in a single training round. Indeed, it is difficult to hide a local update by adding other independent local updates when the updates are of high dimension. Our findings underscore the imperative for additional privacy-enhancing mechanisms, such as noise injection, in federated learning.
引用
收藏
页码:180 / 198
页数:19
相关论文
共 50 条
[21]   Secure Aggregation is Insecure: Category Inference Attack on Federated Learning [J].
Gao, Jiqiang ;
Hou, Boyu ;
Guo, Xiaojie ;
Liu, Zheli ;
Zhang, Ying ;
Chen, Kai ;
Li, Jin .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (01) :147-160
[22]   Comparative Analysis of Membership Inference Attacks in Federated and Centralized Learning [J].
Abbasi Tadi, Ali ;
Dayal, Saroj ;
Alhadidi, Dima ;
Mohammed, Noman .
INFORMATION, 2023, 14 (11)
[23]   Differentially Private Tripartite Intelligent Matching Against Inference Attacks in Ride-Sharing Services [J].
He, Yuanyuan ;
Ni, Jianbing ;
Yang, Laurence T. ;
Wei, Wei ;
Deng, Xianjun ;
Zou, Deqing ;
Ahmed, Syed Hassan .
IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2022, 23 (11) :22583-22595
[24]   Membership Inference Against DNA Methylation Databases [J].
Hagestedt, Inken ;
Humbert, Mathias ;
Berrang, Pascal ;
Lehmann, Irina ;
Eils, Roland ;
Backes, Michael ;
Zhang, Yang .
2020 5TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P 2020), 2020, :508-520
[25]   SAFELearn: Secure Aggregation for private FEderated Learning [J].
Fereidooni, Hossein ;
Marchal, Samuel ;
Miettinen, Markus ;
Mirhoseini, Azalia ;
Moellering, Helen ;
Thien Duc Nguyen ;
Rieger, Phillip ;
Sadeghi, Ahmad-Reza ;
Schneider, Thomas ;
Yalame, Hossein ;
Zeitouni, Shaza .
2021 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2021), 2021, :56-62
[26]   Assessment of data augmentation, dropout with L2 Regularization and differential privacy against membership inference attacks [J].
Ben Hamida, Sana ;
Mrabet, Hichem ;
Chaieb, Faten ;
Jemai, Abderrazak .
MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 83 (15) :44455-44484
[27]   Assessment of data augmentation, dropout with L2 Regularization and differential privacy against membership inference attacks [J].
Sana Ben Hamida ;
Hichem Mrabet ;
Faten Chaieb ;
Abderrazak Jemai .
Multimedia Tools and Applications, 2024, 83 :44455-44484
[28]   Enhancing Deep Learning Model Privacy Against Membership Inference Attacks Using Privacy-Preserving Oversampling [J].
Subhasish Ghosh ;
Amit Kr Mandal ;
Agostino Cortesi .
SN Computer Science, 6 (4)
[29]   Assessing Differentially Private Variational Autoencoders Under Membership Inference [J].
Bernau, Daniel ;
Robl, Jonas ;
Kerschbaum, Florian .
DATA AND APPLICATIONS SECURITY AND PRIVACY XXXVI, DBSEC 2022, 2022, 13383 :3-14
[30]   Membership inference attack on differentially private block coordinate descent [J].
Riaz S. ;
Ali S. ;
Wang G. ;
Latif M.A. ;
Iqbal M.Z. .
PeerJ Computer Science, 2023, 9