GAN-based data reconstruction attacks in split learning

被引:0
|
作者
Zeng, Bo [1 ]
Luo, Sida [1 ]
Yu, Fangchao [1 ]
Yang, Geying [1 ]
Zhao, Kai [1 ]
Wang, Lina [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Peoples R China
基金
中国国家自然科学基金;
关键词
Distributed privacy-preserving machine; learning; Split learning; Data reconstruction attacks; Model inversion; Generative adversarial networks;
D O I
10.1016/j.neunet.2025.107150
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the distinctive distributed privacy-preserving architecture, split learning has found widespread application in scenarios where computational resources on the client side are limited. Unlike clients in federated learning retaining the whole model, split learning partitions the model into two segments situated separately on the server and client ends, thereby preventing direct access to the complete model structure by either party and fortifying its resilience against attacks. However, existing studies have demonstrated that even with access restricted to partial model outputs, split learning remains susceptible to data reconstruction attacks. This vulnerability persists despite prior research predominantly relying on stringent assumptions and the attacker being the server with the ability to access global information. Building upon this understanding, we devise GAN-based data reconstruction attacks within the U-shaped split learning framework, meticulously examining and confirming the feasibility of attacks initiated from both server and client sides, along with the underlying assumptions. Specifically, for attacks originating from the server, we propose the Model Approximation E stimation Reconstruction Attack (MAERA) to mitigate the requisite prior assumptions, and we also introduce the Distillation-based Client-side Reconstruction Attack (DCRA) to execute data reconstructions from the client for the first time. Experimental results illustrate the effectiveness and the robustness of the proposed frameworks in launching attacks across various datasets. In particular, MAERA necessitates merely 1% of the test set samples and 1% of the private data samples from the CIFAR100 dataset to unleash effective attacks, while DCRA adeptly expropriates models from clients and yields more pronounced reconstruction effects on target class samples during the process of inferring data distribution characteristics, in contrast to conventional Maximum A Posteriori (MAP) estimation algorithms.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] Study of GAN-based image reconstruction for diffractive optical systems
    Evdokimova, Viktoriia
    Petrov, Maksim
    Klyueva, Marina
    Firsov, Nikita
    Bibikov, Sergei
    Skidanov, Roman
    Popov, Sergei
    Nikonorov, Artem
    2020 VI INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND NANOTECHNOLOGY (IEEE ITNT-2020), 2020,
  • [22] Counter-act against GAN-based attacks: A collaborative learning approach for anti-forensic detection
    Uddin, Kutub
    Jeong, Tae Hyun
    Oh, Byung Tae
    APPLIED SOFT COMPUTING, 2024, 153
  • [23] Inference attacks based on GAN in federated learning
    Trung Ha
    Tran Khanh Dang
    INTERNATIONAL JOURNAL OF WEB INFORMATION SYSTEMS, 2022, 18 (2/3) : 117 - 136
  • [24] GAN-Based Planning Model in Deep Reinforcement Learning
    Chen, Song
    Jiang, Junpeng
    Zhang, Xiaofang
    Wu, Jinjin
    Lu, Gongzheng
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2020, PT II, 2020, 12397 : 323 - 334
  • [25] Detecting GAN-based Privacy Attack in Distributed Learning
    Xiong, Yayuan
    Xu, Fengyuan
    Thong, Sheng
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [26] GAN-Based Priors for Quantifying Uncertainty in Supervised Learning
    Patel, Dhruv V.
    Oberai, Assad A.
    SIAM-ASA JOURNAL ON UNCERTAINTY QUANTIFICATION, 2021, 9 (03): : 1314 - 1343
  • [27] GAN-based tone curve learning for colour transfer
    Ito, D.
    Sasaki, R.
    Uruma, K.
    ELECTRONICS LETTERS, 2022, 58 (16) : 609 - 611
  • [28] GAN-based Gaussian Mixture Model Responsibility Learning
    Huang, Wanming
    Da Xu, Richard Yi
    Jiang, Shuai
    Liang, Xuan
    Oppermann, Ian
    2020 25TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2021, : 3467 - 3474
  • [29] GAN-based imbalanced data intrusion detection system
    JooHwa Lee
    KeeHyun Park
    Personal and Ubiquitous Computing, 2021, 25 : 121 - 128
  • [30] Privacy preservation for image data: A GAN-based method
    Chen, Zhenfei
    Zhu, Tianqing
    Xiong, Ping
    Wang, Chenguang
    Ren, Wei
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2021, 36 (04) : 1668 - 1685