Semantic Scholar Open Access 2023 24 sitasi

CGIR: Conditional Generative Instance Reconstruction Attacks Against Federated Learning

Xiangrui Xu Peng Liu Wei Wang Hongliang Ma Bin Wang +2 lainnya

Abstrak

Data reconstruction attack has become an emerging privacy threat to Federal Learning (FL), inspiring a rethinking of FL's ability to protect privacy. While existing data reconstruction attacks have shown some effective performance, prior arts rely on different strong assumptions to guide the reconstruction process. In this work, we propose a novel Conditional Generative Instance Reconstruction Attack (CGIR attack) that drops all these assumptions. Specifically, we propose a batch label inference attack in non-IID FL scenarios, where multiple images can share the same labels. Based on the inferred labels, we conduct a “coarse-to-fine” image reconstruction process that provides a stable and effective data reconstruction. In addition, we equip the generator with a label condition restriction so that the contents and the labels of the reconstructed images are consistent. Our extensive evaluation results on two model architectures and five image datasets show that without the auxiliary assumptions, the CGIR attack outperforms the prior arts, even for complex datasets, deep models, and large batch sizes. Furthermore, we evaluate several existing defense methods. The experimental results suggest that pruning gradients can be used as a strategy to mitigate privacy risks in FL if a model tolerates a slight accuracy loss.

Topik & Kata Kunci

Penulis (7)

X

Xiangrui Xu

P

Peng Liu

W

Wei Wang

H

Hongliang Ma

B

Bin Wang

Z

Zhen Han

Y

Yufei Han

Format Sitasi

Xu, X., Liu, P., Wang, W., Ma, H., Wang, B., Han, Z. et al. (2023). CGIR: Conditional Generative Instance Reconstruction Attacks Against Federated Learning. https://doi.org/10.1109/TDSC.2022.3228302

Akses Cepat

PDF tidak tersedia langsung

Cek di sumber asli →
Lihat di Sumber doi.org/10.1109/TDSC.2022.3228302
Informasi Jurnal
Tahun Terbit
2023
Bahasa
en
Total Sitasi
24×
Sumber Database
Semantic Scholar
DOI
10.1109/TDSC.2022.3228302
Akses
Open Access ✓