Fool Attackers by Imperceptible Noise: A Privacy-Preserving Adversarial Representation Mechanism for Collaborative Learning

被引:0
|
作者
Ruan, Na [1 ]
Chen, Jikun [1 ]
Huang, Tu [1 ]
Sun, Zekun [1 ]
Li, Jie [1 ]
机构
[1] Shanghai Jiao Tong Univ, Dept Comp Sci, Shanghai 200240, Peoples R China
基金
国家重点研发计划;
关键词
Federated learning; Data models; Training; Task analysis; Noise; Privacy; Data privacy; collaborative learning; adversarial examples; quantification;
D O I
10.1109/TMC.2024.3405548
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The performance of deep learning models highly depends on the amount of training data. It is common practice for today's data holders to merge their datasets and train models collaboratively, which yet poses a threat to data privacy. Different from existing methods, such as secure multi-party computation (MPC) and federated learning (FL), we find representation learning has unique advantages in collaborative learning due to its low privacy budget, wide applicability to tasks and lower communication overhead. However, data representations face the threat of model inversion attacks. In this article, we formally define the collaborative learning scenario, and present ARS (for adversarial representation sharing), a collaborative learning framework wherein users share representations of data to train models, and add imperceptible adversarial noise to data representations against reconstruction or attribute extraction attacks. By theoretical analysis and evaluating ARS in different contexts, we demonstrate that our mechanism is effective against model inversion attacks, and can achieve great utility and low communication complexity while preserving data privacy. Moreover, the ARS framework has wide applicability, which can be easily extended to the vertical data partitioning scenario and utilized in different tasks.
引用
收藏
页码:11839 / 11852
页数:14
相关论文
共 50 条
  • [31] Privacy-Preserving Classification on Deep Learning with Exponential Mechanism
    Ju, Quan
    Xia, Rongqing
    Li, Shuhong
    Zhang, Xiaojian
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2024, 17 (01)
  • [32] Privacy-Preserving Correlated Data Publication with a Noise Adding Mechanism
    Sun, Mingjing
    Zhao, Chengcheng
    He, Jianping
    2020 IEEE 16TH INTERNATIONAL CONFERENCE ON CONTROL & AUTOMATION (ICCA), 2020, : 494 - 499
  • [33] FAME: A Federated Adversarial Learning Framework for Privacy-Preserving MRI Reconstruction
    Ahmed, Shahzad
    Feng, Jinchao
    Ferzund, Javed
    Yaqub, Muhammad
    Ali, Muhammad Usman
    Manan, Malik Abdul
    Raheem, Abdul
    APPLIED MAGNETIC RESONANCE, 2025,
  • [34] Multi-objective Privacy-preserving Text Representation Learning
    Zhan, Huixin
    Zhang, Kun
    Hu, Chenyi
    Sheng, Victor S.
    PROCEEDINGS OF THE 30TH ACM INTERNATIONAL CONFERENCE ON INFORMATION & KNOWLEDGE MANAGEMENT, CIKM 2021, 2021, : 3612 - 3616
  • [35] Privacy-Preserving Classification on Deep Learning with Exponential Mechanism
    Quan Ju
    Rongqing Xia
    Shuhong Li
    Xiaojian Zhang
    International Journal of Computational Intelligence Systems, 17
  • [36] Privacy-Preserving Representation Learning on Graphs: A Mutual Information Perspective
    Wang, Binghui
    Guo, Jiayi
    Li, Ang
    Chen, Yiran
    Li, Hai
    KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 1667 - 1676
  • [37] Graph Privacy Funnel: A Variational Approach for Privacy-Preserving Representation Learning on Graphs
    Lin, Wanyu
    Lan, Hao
    Cao, Jiannong
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 967 - 978
  • [38] Privacy-preserving collaborative data mining
    Zhan, J
    Chang, LW
    Matwin, S
    FOUNDATIONS AND NOVEL APPROACHES IN DATA MINING, 2006, 9 : 213 - +
  • [39] Privacy-preserving collaborative social networks
    Zhan, Justin
    Blosser, Gary
    Yang, Chris
    Singh, Lisa
    INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2008, 5075 : 114 - +
  • [40] Privacy-preserving distributed collaborative filtering
    Boutet, Antoine
    Frey, Davide
    Guerraoui, Rachid
    Jegou, Arnaud
    Kermarrec, Anne-Marie
    COMPUTING, 2016, 98 (08) : 827 - 846