GAN-based data reconstruction attacks in split learning

被引:0
|
作者
Zeng, Bo [1 ]
Luo, Sida [1 ]
Yu, Fangchao [1 ]
Yang, Geying [1 ]
Zhao, Kai [1 ]
Wang, Lina [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Peoples R China
基金
中国国家自然科学基金;
关键词
Distributed privacy-preserving machine; learning; Split learning; Data reconstruction attacks; Model inversion; Generative adversarial networks;
D O I
10.1016/j.neunet.2025.107150
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the distinctive distributed privacy-preserving architecture, split learning has found widespread application in scenarios where computational resources on the client side are limited. Unlike clients in federated learning retaining the whole model, split learning partitions the model into two segments situated separately on the server and client ends, thereby preventing direct access to the complete model structure by either party and fortifying its resilience against attacks. However, existing studies have demonstrated that even with access restricted to partial model outputs, split learning remains susceptible to data reconstruction attacks. This vulnerability persists despite prior research predominantly relying on stringent assumptions and the attacker being the server with the ability to access global information. Building upon this understanding, we devise GAN-based data reconstruction attacks within the U-shaped split learning framework, meticulously examining and confirming the feasibility of attacks initiated from both server and client sides, along with the underlying assumptions. Specifically, for attacks originating from the server, we propose the Model Approximation E stimation Reconstruction Attack (MAERA) to mitigate the requisite prior assumptions, and we also introduce the Distillation-based Client-side Reconstruction Attack (DCRA) to execute data reconstructions from the client for the first time. Experimental results illustrate the effectiveness and the robustness of the proposed frameworks in launching attacks across various datasets. In particular, MAERA necessitates merely 1% of the test set samples and 1% of the private data samples from the CIFAR100 dataset to unleash effective attacks, while DCRA adeptly expropriates models from clients and yields more pronounced reconstruction effects on target class samples during the process of inferring data distribution characteristics, in contrast to conventional Maximum A Posteriori (MAP) estimation algorithms.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] GAN-Based Synthetic Data Augmentation for Infrared Small Target Detection
    Kim, Jun-Hyung
    Hwang, Youngbae
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2022, 60
  • [22] Antenna Design Using a GAN-Based Synthetic Data Generation Approach
    Noakoasteen, Oameed
    Vijayamohanan, Jayakrishnan
    Gupta, Arjun
    Christodoulou, Christos
    IEEE OPEN JOURNAL OF ANTENNAS AND PROPAGATION, 2022, 3 : 488 - 494
  • [23] Towards Post-disaster Damage Assessment using Deep Transfer Learning and GAN-based Data Augmentation
    Banerjee, Sourasekhar
    Patel, Yashwant Singh
    Kumar, Pushkar
    Bhuyan, Monowar
    PROCEEDINGS OF THE 24TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING, ICDCN 2023, 2023, : 372 - 377
  • [24] Studies on the GAN-Based Anomaly Detection Methods for the Time Series Data
    Lee, Chang-Ki
    Cheon, Yu-Jeong
    Hwang, Wook-Yeon
    IEEE ACCESS, 2021, 9 : 73201 - 73215
  • [25] A Review of GAN-Based Super-Resolution Reconstruction for Optical Remote Sensing Images
    Wang, Xuan
    Sun, Lijun
    Chehri, Abdellah
    Song, Yongchao
    REMOTE SENSING, 2023, 15 (20)
  • [26] Towards privacy-preserving split learning: Destabilizing adversarial inference and reconstruction attacks in the cloud
    Higgins, Griffin
    Razavi-Far, Roozbeh
    Zhang, Xichen
    David, Amir
    Ghorbani, Ali
    Ge, Tongyu
    INTERNET OF THINGS, 2025, 31
  • [27] GAN-Driven Data Poisoning Attacks and Their Mitigation in Federated Learning Systems
    Psychogyios, Konstantinos
    Velivassaki, Terpsichori-Helen
    Bourou, Stavroula
    Voulkidis, Artemis
    Skias, Dimitrios
    Zahariadis, Theodore
    ELECTRONICS, 2023, 12 (08)
  • [28] Strengthening IDS against Evasion Attacks with GAN-based Adversarial Samples in SDN-enabled network
    Cao Phan Xuan Qui
    Dang Hong Quang
    Phan The Duy
    Do Thi Thu Hien
    Van-Hau Pham
    2021 RIVF INTERNATIONAL CONFERENCE ON COMPUTING AND COMMUNICATION TECHNOLOGIES (RIVF 2021), 2021, : 192 - 197
  • [29] Robotic Object Manipulation with Full-Trajectory GAN-Based Imitation Learning
    Wang, Haoxu
    Meger, David
    2021 18TH CONFERENCE ON ROBOTS AND VISION (CRV 2021), 2021, : 57 - 63
  • [30] GAN-Based Face Attribute Editing
    Liu, Shuang
    Li, Dan
    Cao, Tianchi
    Sun, Yuke
    Hu, Yingsong
    Ji, Junwen
    IEEE ACCESS, 2020, 8 : 34854 - 34867