Trojan attribute inference attack on gradient boosting decision trees

被引:0
|
作者
Ito, Kunihiro [1 ]
Enkhtaivan, Batnyam [1 ]
Teranishi, Isamu [1 ]
Sakuma, Jun [2 ]
机构
[1] NEC Corp Ltd, Kawasaki, Kanagawa, Japan
[2] Tokyo Inst Technol, RIKEN, Meguro Ku, Tokyo, Japan
关键词
D O I
10.1109/EuroSP60621.2024.00036
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We propose a Trojan horse-type attribute inference attack (AIA) against the gradient boosting decision trees (GBDT) in the federated learning setting. Our Trojan AIA consists of a Trojan tree creation and an attribute inference. Both algorithms leverage the characteristics of the federated learning protocol for the GBDT training. First, the adversary creates a decision tree, a Trojan tree, that isolates a target data record from other data records. The adversary sends the Trojan tree to the server through the federated learning protocol at their round. Trojan tree forces the victim's tree to "memorize" a target attribute value of target data record that the adversary wants to know. The adversary can recover the target attribute value by observing the tree submitted by the victim if the victim uses the target data record for training the tree. For the regression task, we derive sufficient conditions for a successful attack. According to our theorem, if the target data record is distinct in the victim's dataset, the proposed attack is always successful. Experiments on multiple datasets and settings show results that align with the above theoretical analysis. Even if some conditions for theoretical analysis are relaxed, the proposed attack outperforms baseline attacks. To the best of our knowledge, this is the first study of an attribute inference attack against the GBDT in the federated learning setting.
引用
收藏
页码:542 / 559
页数:18
相关论文
共 50 条
  • [1] Booster: An Accelerator for Gradient Boosting Decision Trees Training and Inference
    He, Mingxuan
    Thottethodi, Mithuna
    Vijaykumar, T. N.
    2022 IEEE 36TH INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM (IPDPS 2022), 2022, : 1051 - 1062
  • [2] Machine Unlearning in Gradient Boosting Decision Trees
    Lin, Huawei
    Chung, Jun Woo
    Lao, Yingjie
    Zhao, Weijie
    PROCEEDINGS OF THE 29TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2023, 2023, : 1374 - 1383
  • [3] Label Aggregation of Gradient Boosting Decision Trees
    Xiang, X. C.
    Zhang, H. X.
    Xia, S. T.
    PROCEEDINGS OF 2020 2ND INTERNATIONAL CONFERENCE ON IMAGE PROCESSING AND MACHINE VISION AND INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION AND MACHINE LEARNING, IPMV 2020, 2020, : 140 - 145
  • [4] FPGA Accelerator for Gradient Boosting Decision Trees
    Alcolea, Adrian
    Resano, Javier
    ELECTRONICS, 2021, 10 (03) : 1 - 15
  • [5] On Incremental Learning for Gradient Boosting Decision Trees
    Zhang, Chongsheng
    Zhang, Yuan
    Shi, Xianjin
    Almpanidis, George
    Fan, Gaojuan
    Shen, Xiajiong
    NEURAL PROCESSING LETTERS, 2019, 50 (01) : 957 - 987
  • [6] Gradient Boosting Decision Trees for Echocardiogram Images
    de Melo, Vinicius Veloso
    Ushizima, Daniela Mayumi
    Baracho, Salety Ferreira
    Coelho, Regina Celia
    2018 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2018,
  • [7] Practical Federated Gradient Boosting Decision Trees
    Li, Qinbin
    Wen, Zeyi
    He, Bingsheng
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 4642 - 4649
  • [8] On Incremental Learning for Gradient Boosting Decision Trees
    Chongsheng Zhang
    Yuan Zhang
    Xianjin Shi
    George Almpanidis
    Gaojuan Fan
    Xiajiong Shen
    Neural Processing Letters, 2019, 50 : 957 - 987
  • [9] Quantized Training of Gradient Boosting Decision Trees
    Shi, Yu
    Ke, Guolin
    Chen, Zhuoming
    Zheng, Shuxin
    Liu, Tie-Yan
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35, NEURIPS 2022, 2022,
  • [10] Efficient Integer-Only-Inference of Gradient Boosting Decision Trees on Low-Power Devices
    Alsharari, Majed
    Mai, Son T.
    Woods, Roger
    Reano, Carlos
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS I-REGULAR PAPERS, 2025, 72 (01) : 241 - 253