GAN-based data reconstruction attacks in split learning

被引:0
|
作者
Zeng, Bo [1 ]
Luo, Sida [1 ]
Yu, Fangchao [1 ]
Yang, Geying [1 ]
Zhao, Kai [1 ]
Wang, Lina [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Peoples R China
基金
中国国家自然科学基金;
关键词
Distributed privacy-preserving machine; learning; Split learning; Data reconstruction attacks; Model inversion; Generative adversarial networks;
D O I
10.1016/j.neunet.2025.107150
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the distinctive distributed privacy-preserving architecture, split learning has found widespread application in scenarios where computational resources on the client side are limited. Unlike clients in federated learning retaining the whole model, split learning partitions the model into two segments situated separately on the server and client ends, thereby preventing direct access to the complete model structure by either party and fortifying its resilience against attacks. However, existing studies have demonstrated that even with access restricted to partial model outputs, split learning remains susceptible to data reconstruction attacks. This vulnerability persists despite prior research predominantly relying on stringent assumptions and the attacker being the server with the ability to access global information. Building upon this understanding, we devise GAN-based data reconstruction attacks within the U-shaped split learning framework, meticulously examining and confirming the feasibility of attacks initiated from both server and client sides, along with the underlying assumptions. Specifically, for attacks originating from the server, we propose the Model Approximation E stimation Reconstruction Attack (MAERA) to mitigate the requisite prior assumptions, and we also introduce the Distillation-based Client-side Reconstruction Attack (DCRA) to execute data reconstructions from the client for the first time. Experimental results illustrate the effectiveness and the robustness of the proposed frameworks in launching attacks across various datasets. In particular, MAERA necessitates merely 1% of the test set samples and 1% of the private data samples from the CIFAR100 dataset to unleash effective attacks, while DCRA adeptly expropriates models from clients and yields more pronounced reconstruction effects on target class samples during the process of inferring data distribution characteristics, in contrast to conventional Maximum A Posteriori (MAP) estimation algorithms.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] On feasibility of GAN-based fingerprint morphing
    Makrushin, Andrey
    Trebeljahr, Mark
    Seidlitz, Stefan
    Dittmann, Jana
    IEEE MMSP 2021: 2021 IEEE 23RD INTERNATIONAL WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING (MMSP), 2021,
  • [32] A GAN-Based Data Injection Attack Method on Data-Driven Strategies in Power Systems
    Liu, Zengji
    Wang, Qi
    Ye, Yujian
    Tang, Yi
    IEEE TRANSACTIONS ON SMART GRID, 2022, 13 (04) : 3203 - 3213
  • [33] GAN-Based Facial Attribute Manipulation
    Liu, Yunfan
    Li, Qi
    Deng, Qiyao
    Sun, Zhenan
    Yang, Ming-Hsuan
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (12) : 14590 - 14610
  • [34] GAN-Based Ultrasound Localization Microscopy
    Gu, Wenting
    Yan, Zhuangzhi
    Li, Boyi
    Liu, Chengcheng
    Ta, Dean
    Liu, Xin
    2022 IEEE INTERNATIONAL ULTRASONICS SYMPOSIUM (IEEE IUS), 2022,
  • [35] A Hybrid GAN-Based Approach to Solve Imbalanced Data Problem in Recommendation Systems
    Shafqat, Wafa
    Byun, Yung-Cheol
    IEEE ACCESS, 2022, 10 : 11036 - 11047
  • [36] GAN-Based Temporal Association Rule Mining on Multivariate Time Series Data
    He, Guoliang
    Dai, Lifang
    Yu, Zhiwen
    Chen, C. L. Philip
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (10) : 5168 - 5180
  • [37] Optimized automated cardiac MR scar quantification with GAN-based data augmentation
    Lustermans, Didier R. P. R. M.
    Amirrajab, Sina
    Veta, Mitko
    Breeuwer, Marcel
    Scannell, Cian M.
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2022, 226
  • [38] SplitGuard: Detecting and Mitigating Training-Hijacking Attacks in Split Learning
    Erdogan, Ege
    Kupcu, Alptekin
    Cicek, A. Ercument
    PROCEEDINGS OF THE 21ST WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2022, 2022, : 125 - 137
  • [39] GAN Supervised Seismic Data Reconstruction: An Enhanced Learning for Improved Generalization
    Goyes-Penafiel, Paul
    Suarez-Rodriguez, Leon
    Correa, Claudia V.
    Arguello, Henry
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62
  • [40] A lightweight GAN-based fault diagnosis method based on knowledge distillation and deep transfer learning
    Zhong, Hongyu
    Yu, Samson
    Trinh, Hieu
    Yuan, Rui
    Lv, Yong
    Wang, Yanan
    MEASUREMENT SCIENCE AND TECHNOLOGY, 2024, 35 (03)