GAN-based data reconstruction attacks in split learning

被引:0
|
作者
Zeng, Bo [1 ]
Luo, Sida [1 ]
Yu, Fangchao [1 ]
Yang, Geying [1 ]
Zhao, Kai [1 ]
Wang, Lina [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Peoples R China
基金
中国国家自然科学基金;
关键词
Distributed privacy-preserving machine; learning; Split learning; Data reconstruction attacks; Model inversion; Generative adversarial networks;
D O I
10.1016/j.neunet.2025.107150
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the distinctive distributed privacy-preserving architecture, split learning has found widespread application in scenarios where computational resources on the client side are limited. Unlike clients in federated learning retaining the whole model, split learning partitions the model into two segments situated separately on the server and client ends, thereby preventing direct access to the complete model structure by either party and fortifying its resilience against attacks. However, existing studies have demonstrated that even with access restricted to partial model outputs, split learning remains susceptible to data reconstruction attacks. This vulnerability persists despite prior research predominantly relying on stringent assumptions and the attacker being the server with the ability to access global information. Building upon this understanding, we devise GAN-based data reconstruction attacks within the U-shaped split learning framework, meticulously examining and confirming the feasibility of attacks initiated from both server and client sides, along with the underlying assumptions. Specifically, for attacks originating from the server, we propose the Model Approximation E stimation Reconstruction Attack (MAERA) to mitigate the requisite prior assumptions, and we also introduce the Distillation-based Client-side Reconstruction Attack (DCRA) to execute data reconstructions from the client for the first time. Experimental results illustrate the effectiveness and the robustness of the proposed frameworks in launching attacks across various datasets. In particular, MAERA necessitates merely 1% of the test set samples and 1% of the private data samples from the CIFAR100 dataset to unleash effective attacks, while DCRA adeptly expropriates models from clients and yields more pronounced reconstruction effects on target class samples during the process of inferring data distribution characteristics, in contrast to conventional Maximum A Posteriori (MAP) estimation algorithms.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] GAN-based one dimensional medical data augmentation
    Ye Zhang
    Zhixiang Wang
    Zhen Zhang
    Junzhuo Liu
    Ying Feng
    Leonard Wee
    Andre Dekker
    Qiaosong Chen
    Alberto Traverso
    Soft Computing, 2023, 27 : 10481 - 10491
  • [32] A Wasserstein GAN-based Framework for Adversarial Attacks against Intrusion Detection Systems
    Cui, Fangda
    Ye, Qiang
    Kibenge-MacLeod, Patricia
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 3187 - 3192
  • [33] GAN-based one dimensional medical data augmentation
    Zhang, Ye
    Wang, Zhixiang
    Zhang, Zhen
    Liu, Junzhuo
    Feng, Ying
    Wee, Leonard
    Dekker, Andre
    Chen, Qiaosong
    Traverso, Alberto
    SOFT COMPUTING, 2023, 27 (15) : 10481 - 10491
  • [34] GAN-based Data Generation for Speech Emotion Recognition
    Eskimez, Sefik Emre
    Dimitriadis, Dimitrios
    Gmyr, Robert
    Kumanati, Kenichi
    INTERSPEECH 2020, 2020, : 3446 - 3450
  • [35] GAN-Based Robust Motion Planning for Mobile Robots Against Localization Attacks
    Tang, Wenbing
    Zhou, Yuan
    Sun, Haiying
    Zhang, Yuhong
    Liu, Yang
    Ding, Zuohua
    Liu, Jing
    He, Jifeng
    IEEE ROBOTICS AND AUTOMATION LETTERS, 2023, 8 (03) : 1603 - 1610
  • [36] An Efficient Distributed Intrusion Detection System in IoT: GAN-based Attacks and a Countermeasure
    Gupta, Neha
    Shojafar, Mohammad
    Foh, Chuan Heng
    Tafazolli, Rahim
    2023 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS, 2023, : 1824 - 1829
  • [37] A mixer architecture using GaN-based split-gate nanowire transistor
    Jha, Jaya
    Surapaneni, Sreenadh
    Ganguly, Swaroop
    Saha, Dipankar
    NANOTECHNOLOGY, 2024, 35 (41)
  • [38] GAN-based imbalanced data intrusion detection system
    Lee, JooHwa
    Park, KeeHyun
    PERSONAL AND UBIQUITOUS COMPUTING, 2021, 25 (01) : 121 - 128
  • [39] LLP-GAN: A GAN-Based Algorithm for Learning From Label Proportions
    Liu, Jiabin
    Wang, Bo
    Hang, Hanyuan
    Wang, Huadong
    Qi, Zhiquan
    Tian, Yingjie
    Shi, Yong
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2023, 34 (11) : 8377 - 8388
  • [40] A GAN-Based Approach for ECG Reconstruction from Doppler Sensor Signals
    Bouazizi, Mondher
    Yu, Danyuan
    Feghoul, Kevin
    Ohtsuki, Tomoaki
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 3867 - 3872