Fool Attackers by Imperceptible Noise: A Privacy-Preserving Adversarial Representation Mechanism for Collaborative Learning

被引:0
|
作者
Ruan, Na [1 ]
Chen, Jikun [1 ]
Huang, Tu [1 ]
Sun, Zekun [1 ]
Li, Jie [1 ]
机构
[1] Shanghai Jiao Tong Univ, Dept Comp Sci, Shanghai 200240, Peoples R China
基金
国家重点研发计划;
关键词
Federated learning; Data models; Training; Task analysis; Noise; Privacy; Data privacy; collaborative learning; adversarial examples; quantification;
D O I
10.1109/TMC.2024.3405548
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The performance of deep learning models highly depends on the amount of training data. It is common practice for today's data holders to merge their datasets and train models collaboratively, which yet poses a threat to data privacy. Different from existing methods, such as secure multi-party computation (MPC) and federated learning (FL), we find representation learning has unique advantages in collaborative learning due to its low privacy budget, wide applicability to tasks and lower communication overhead. However, data representations face the threat of model inversion attacks. In this article, we formally define the collaborative learning scenario, and present ARS (for adversarial representation sharing), a collaborative learning framework wherein users share representations of data to train models, and add imperceptible adversarial noise to data representations against reconstruction or attribute extraction attacks. By theoretical analysis and evaluating ARS in different contexts, we demonstrate that our mechanism is effective against model inversion attacks, and can achieve great utility and low communication complexity while preserving data privacy. Moreover, the ARS framework has wide applicability, which can be easily extended to the vertical data partitioning scenario and utilized in different tasks.
引用
收藏
页码:11839 / 11852
页数:14
相关论文
共 50 条
  • [41] PRIVACY-PRESERVING COLLABORATIVE DATA MINING
    Zhan, Justin
    KMIS 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON KNOWLEDGE MANAGEMENT AND INFORMATION SHARING, 2009, : IS15 - IS15
  • [42] Privacy-preserving distributed collaborative filtering
    Antoine Boutet
    Davide Frey
    Rachid Guerraoui
    Arnaud Jégou
    Anne-Marie Kermarrec
    Computing, 2016, 98 : 827 - 846
  • [43] PRIVACY-PRESERVING COLLABORATIVE DATA MINING
    Zhan, Justin
    KDIR 2009: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND INFORMATION RETRIEVAL, 2009, : IS15 - IS15
  • [44] Privacy-Preserving Collaborative Filtering Schemes
    Kikuchi, Hiroaki
    Kizawa, Hiroyasu
    Tada, Minako
    2009 INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY (ARES), VOLS 1 AND 2, 2009, : 911 - 916
  • [45] Privacy-Preserving Collaborative Recommender Systems
    Zhan, Justin
    Hsieh, Chia-Lung
    Wang, I-Cheng
    Hsu, Tsan-Sheng
    Liau, Churn-Jung
    Wang, Da-Wei
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS PART C-APPLICATIONS AND REVIEWS, 2010, 40 (04): : 472 - 476
  • [46] Privacy-Preserving Enhanced Collaborative Tagging
    Parra-Arnau, Javier
    Perego, Andrea
    Ferrari, Elena
    Forne, Jordi
    Rebollo-Monedero, David
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2014, 26 (01) : 180 - 193
  • [47] Privacy-preserving collaborative fuzzy clustering
    Lyu, Lingjuan
    Bezdek, James C.
    Law, Yee Wei
    He, Xuanli
    Palaniswami, Marimuthu
    DATA & KNOWLEDGE ENGINEERING, 2018, 116 : 21 - 41
  • [48] Privacy-preserving collaborative data mining
    Zhan, Justin
    IEEE COMPUTATIONAL INTELLIGENCE MAGAZINE, 2008, 3 (02) : 31 - 41
  • [49] PPGAN: Privacy-preserving Generative Adversarial Network
    Liu, Yi
    Peng, Jialiang
    Yu, James J. Q.
    Wu, Yi
    2019 IEEE 25TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2019, : 985 - 989
  • [50] Privacy-Preserving Scoring Mechanism
    Jia, Zhuliang
    Zhao, Xueling
    Pan, Jiahao
    International Journal of Network Security, 2022, 24 (06) : 1015 - 1019