A defense mechanism against label inference attacks in Vertical Federated Learning

被引:0
|
作者
Arazzi, Marco [1 ]
Nicolazzo, Serena [2 ]
Nocera, Antonino [1 ]
机构
[1] Univ Pavia, Dept Elect Comp & Biomed Engn, Via A Ferrata 5, I-27100 Pavia, PV, Italy
[2] Univ Milan, Dept Comp Sci, Via G Celoria 18, I-20133 Milan, MI, Italy
关键词
Federated learning; Vertical Federated Learning; VFL; Label inference attack; Knowledge distillation; k-anonymity;
D O I
10.1016/j.neucom.2025.129476
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Vertical Federated Learning (VFL, for short) is a category of Federated Learning that is gaining increasing attention in the context of Artificial Intelligence. According to this paradigm, machine/deep learning models are trained collaboratively among parties with vertically partitioned data. Typically, in a VFL scenario, the labels of the samples are kept private from all parties except the aggregating server, that is, the label owner. However, recent work discovered that by exploiting the gradient information returned by the server to bottom models, with the knowledge of only a small set of auxiliary labels on a very limited subset of training data points, an adversary could infer the private labels. These attacks are known as label inference attacks in VFL. In our work, we propose a novel framework called KDk (knowledge distillation with k-anonymity) that combines knowledge distillation and k-anonymity to provide a defense mechanism against potential label inference attacks in a VFL scenario. Through an exhaustive experimental campaign, we demonstrate that by applying our approach, the performance of the analyzed label inference attacks decreases consistently, even by more than 60%, maintaining the accuracy of the whole VFL almost unaltered.
引用
收藏
页数:13
相关论文
共 50 条
  • [21] RoseAgg: Robust Defense Against Targeted Collusion Attacks in Federated Learning
    Yang, He
    Xi, Wei
    Shen, Yuhao
    Wu, Canhui
    Zhao, Jizhong
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 2951 - 2966
  • [22] A Four-Pronged Defense Against Byzantine Attacks in Federated Learning
    Wan, Wei
    Hu, Shengshan
    Li, Minghui
    Lu, Jianrong
    Zhang, Longling
    Zhang, Leo Yu
    Jin, Hai
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 7394 - 7402
  • [23] Source Inference Attacks: Beyond Membership Inference Attacks in Federated Learning
    Hu, Hongsheng
    Zhang, Xuyun
    Salcic, Zoran
    Sun, Lichao
    Choo, Kim-Kwang Raymond
    Dobbie, Gillian
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3012 - 3029
  • [24] HashVFL: Defending Against Data Reconstruction Attacks in Vertical Federated Learning
    Qiu, Pengyu
    Zhang, Xuhong
    Ji, Shouling
    Fu, Chong
    Yang, Xing
    Wang, Ting
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3435 - 3450
  • [25] Efficient Privacy-Preserving Federated Learning Against Inference Attacks for IoT
    Miao, Yifeng
    Chen, Siguang
    2023 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, WCNC, 2023,
  • [26] Defending against Membership Inference Attacks in Federated learning via Adversarial Example
    Xie, Yuanyuan
    Chen, Bing
    Zhang, Jiale
    Wu, Di
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 153 - 160
  • [27] Efficient Membership Inference Attacks against Federated Learning via Bias Differences
    Zhang, Liwei
    Li, Linghui
    Li, Xiaoyong
    Cai, Binsi
    Gao, Yali
    Dou, Ruobin
    Chen, Luying
    PROCEEDINGS OF THE 26TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2023, 2023, : 222 - 235
  • [28] FD-Leaks: Membership Inference Attacks Against Federated Distillation Learning
    Yang, Zilu
    Zhao, Yanchao
    Zhang, Jiale
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 364 - 378
  • [29] Moat: Model Agnostic Defense against Targeted Poisoning Attacks in Federated Learning
    Manna, Arpan
    Kasyap, Harsh
    Tripathy, Somanath
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2021), PT I, 2021, 12918 : 38 - 55
  • [30] Evaluation of Various Defense Techniques Against Targeted Poisoning Attacks in Federated Learning
    Richards, Charles
    Khemani, Sofia
    Li, Feng
    2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 693 - 698