Multi-level membership inference attacks in federated Learning based on active GAN

被引:6
作者
Sui, Hao [1 ,2 ]
Sun, Xiaobing [1 ,2 ]
Zhang, Jiale [1 ,2 ]
Chen, Bing [3 ]
Li, Wenjuan [4 ]
机构
[1] Yangzhou Univ, Sch Informat Engn, Yangzhou 225127, Jiangsu, Peoples R China
[2] Jiangsu Engn Res Ctr Knowledge Management & Intell, Yangzhou 225127, Jiangsu, Peoples R China
[3] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Nanjing 211106, Jiangsu, Peoples R China
[4] Hong Kong Polytech Univ, Dept Elect & Informat Engn, Hong Kong 999077, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; Membership inference attacks; Generative adversarial networks; Active learning;
D O I
10.1007/s00521-023-08593-y
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, federated learning has been widely used in various fields, such as smart healthcare and financial forecast, due to its ability to protect the privacy of user secret data. Although federated learning has the capability of protecting users' data privacy, recent research results demonstrated that federated learning still suffers from many privacy attacks. Among them, membership inference attacks are the most common privacy attacks in which attackers infer whether the record belongs to a member message or not. However, the current studies are unable to provide further depth to infer membership information, meaning that existing attack methods have difficulty deducing specifically which user the record belongs to. Moreover, there is a lack of training data in the training process which seriously impacts the effectiveness of membership inference attacks. In this paper, from the perspective of inferring both model-level and user-level membership information, we not only infer whether a record belongs to members but furthermore identify which member the record belongs to. In addition, we augment the training dataset by leveraging the generative adversarial networks (GANs) approach and address the lack of labeling of the newly generated data with the aid of the active learning approach. To demonstrate the effectiveness of our method, we implement our proposed methods on the five benchmark datasets. Extensive experimental results demonstrate that both model-level and user-level membership inference attacks can be achieved with good effectiveness.
引用
收藏
页码:17013 / 17027
页数:15
相关论文
共 50 条
  • [21] Poster: Membership Inference Attacks via Contrastive Learning
    Chen, Depeng
    Liu, Xiao
    Cui, Jie
    Zhong, Hong
    [J]. PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 3555 - 3557
  • [22] Demystifying Membership Inference Attacks in Machine Learning as a Service
    Truex, Stacey
    Liu, Ling
    Gursoy, Mehmet Emre
    Yu, Lei
    Wei, Wenqi
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2021, 14 (06) : 2073 - 2089
  • [23] KD-GAN: An effective membership inference attacks defence framework
    Zhang, Zhenxin
    Lin, Guanbiao
    Ke, Lishan
    Peng, Shiyu
    Hu, Li
    Yan, Hongyang
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (11) : 9921 - 9935
  • [24] Mitigation of Membership Inference Attack by Knowledge Distillation on Federated Learning
    Ueda, Rei
    Nakai, Tsunato
    Yoshida, Kota
    Fujino, Takeshi
    [J]. IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2025, E108A (03) : 267 - 279
  • [25] CMI: Client-Targeted Membership Inference in Federated Learning
    Zheng, Tianhang
    Li, Baochun
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 4122 - 4132
  • [26] MFLCES: Multi-Level Federated Edge Learning Algorithm Based on Client and Edge Server Selection
    Liu, Zhenpeng
    Duan, Sichen
    Wang, Shuo
    Liu, Yi
    Li, Xiaofei
    [J]. ELECTRONICS, 2023, 12 (12)
  • [27] Membership Inference Vulnerabilities in Peer-to-Peer Federated Learning
    Luqman, Alka
    Chattopadhyay, Anupam
    Lam, Kwok Yan
    [J]. PROCEEDINGS OF THE INAUGURAL ASIACCS 2023 WORKSHOP ON SECURE AND TRUSTWORTHY DEEP LEARNING SYSTEMS, SECTL, 2022,
  • [28] FLEDGE: Ledger-based Federated Learning Resilient to Inference and Backdoor Attacks
    Castillo, Jorge
    Rieger, Phillip
    Fereidooni, Hossein
    Chen, Qian
    Sadeghi, Ahmad-Reza
    [J]. 39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 647 - 661
  • [29] Multi-level Adaptive Active Learning for Scene Classification
    Li, Xin
    Guo, Yuhong
    [J]. COMPUTER VISION - ECCV 2014, PT VII, 2014, 8695 : 234 - 249
  • [30] Prevention of GAN-Based Privacy Inferring Attacks Towards Federated Learning
    Cao, Hongbo
    Zhu, Yongsheng
    Ren, Yuange
    Wang, Bin
    Hu, Mingqing
    Wang, Wanqi
    Wang, Wei
    [J]. COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2022, PT II, 2022, 461 : 39 - 54