GAN-based data reconstruction attacks in split learning

被引:0
|
作者
Zeng, Bo [1 ]
Luo, Sida [1 ]
Yu, Fangchao [1 ]
Yang, Geying [1 ]
Zhao, Kai [1 ]
Wang, Lina [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Peoples R China
基金
中国国家自然科学基金;
关键词
Distributed privacy-preserving machine; learning; Split learning; Data reconstruction attacks; Model inversion; Generative adversarial networks;
D O I
10.1016/j.neunet.2025.107150
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the distinctive distributed privacy-preserving architecture, split learning has found widespread application in scenarios where computational resources on the client side are limited. Unlike clients in federated learning retaining the whole model, split learning partitions the model into two segments situated separately on the server and client ends, thereby preventing direct access to the complete model structure by either party and fortifying its resilience against attacks. However, existing studies have demonstrated that even with access restricted to partial model outputs, split learning remains susceptible to data reconstruction attacks. This vulnerability persists despite prior research predominantly relying on stringent assumptions and the attacker being the server with the ability to access global information. Building upon this understanding, we devise GAN-based data reconstruction attacks within the U-shaped split learning framework, meticulously examining and confirming the feasibility of attacks initiated from both server and client sides, along with the underlying assumptions. Specifically, for attacks originating from the server, we propose the Model Approximation E stimation Reconstruction Attack (MAERA) to mitigate the requisite prior assumptions, and we also introduce the Distillation-based Client-side Reconstruction Attack (DCRA) to execute data reconstructions from the client for the first time. Experimental results illustrate the effectiveness and the robustness of the proposed frameworks in launching attacks across various datasets. In particular, MAERA necessitates merely 1% of the test set samples and 1% of the private data samples from the CIFAR100 dataset to unleash effective attacks, while DCRA adeptly expropriates models from clients and yields more pronounced reconstruction effects on target class samples during the process of inferring data distribution characteristics, in contrast to conventional Maximum A Posteriori (MAP) estimation algorithms.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] GAN-based deep learning framework of network reconstruction
    Xu, Xiang
    Zhu, Xianqiang
    Zhu, Cheng
    COMPLEX & INTELLIGENT SYSTEMS, 2023, 9 (03) : 3131 - 3146
  • [2] GAN-based deep learning framework of network reconstruction
    Xiang Xu
    Xianqiang Zhu
    Cheng Zhu
    Complex & Intelligent Systems, 2023, 9 : 3131 - 3146
  • [3] Prevention of GAN-Based Privacy Inferring Attacks Towards Federated Learning
    Cao, Hongbo
    Zhu, Yongsheng
    Ren, Yuange
    Wang, Bin
    Hu, Mingqing
    Wang, Wanqi
    Wang, Wei
    COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING, COLLABORATECOM 2022, PT II, 2022, 461 : 39 - 54
  • [4] GAN You See Me? Enhanced Data Reconstruction Attacks against Split Inference
    Li, Ziang
    Yang, Mengda
    Liu, Yaxin
    Wang, Juan
    Hu, Hongxin
    Yi, Wenzhe
    Xu, Xiaoyang
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [5] Adversarial attacks on GAN-based image fusion
    Sun, Hui
    Wu, Siman
    Ma, Lijun
    INFORMATION FUSION, 2024, 108
  • [6] GAN-based classifier protection against adversarial attacks
    Liu, Shuqi
    Shao, Mingwen
    Liu, Xinping
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 39 (05) : 7085 - 7095
  • [7] Learning GAN-Based Foveated Reconstruction to Recover Perceptually Important Image Features
    Surace, Luca
    Wernikowski, Marek
    Tursun, Cara
    Myszkowski, Karol
    Mantiuk, Radoslaw
    Didyk, Piotr
    ACM TRANSACTIONS ON APPLIED PERCEPTION, 2023, 20 (02)
  • [8] Conditional Wasserstein GAN-based oversampling of tabular data for imbalanced learning
    Engelmann, Justin
    Lessmann, Stefan
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 174
  • [9] A GAN-Based Defense Framework Against Model Inversion Attacks
    Gong, Xueluan
    Wang, Ziyao
    Li, Shuaike
    Chen, Yanjiao
    Wang, Qian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 4475 - 4487
  • [10] Enhancing IoT cyber attacks intrusion detection through GAN-based data augmentation and hybrid deep learning models for MQTT network protocol cyber attacks
    Zeghida, Hayette
    Boulaiche, Mehdi
    Chikh, Ramdane
    Bamhdi, Alwi M.
    Barros, Ana Luiza Bessa
    Zeghida, Djamel
    Patel, Ahmed
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2025, 28 (01):