GAN-based data reconstruction attacks in split learning

被引:0
|
作者
Zeng, Bo [1 ]
Luo, Sida [1 ]
Yu, Fangchao [1 ]
Yang, Geying [1 ]
Zhao, Kai [1 ]
Wang, Lina [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Wuhan 430072, Peoples R China
基金
中国国家自然科学基金;
关键词
Distributed privacy-preserving machine; learning; Split learning; Data reconstruction attacks; Model inversion; Generative adversarial networks;
D O I
10.1016/j.neunet.2025.107150
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Due to the distinctive distributed privacy-preserving architecture, split learning has found widespread application in scenarios where computational resources on the client side are limited. Unlike clients in federated learning retaining the whole model, split learning partitions the model into two segments situated separately on the server and client ends, thereby preventing direct access to the complete model structure by either party and fortifying its resilience against attacks. However, existing studies have demonstrated that even with access restricted to partial model outputs, split learning remains susceptible to data reconstruction attacks. This vulnerability persists despite prior research predominantly relying on stringent assumptions and the attacker being the server with the ability to access global information. Building upon this understanding, we devise GAN-based data reconstruction attacks within the U-shaped split learning framework, meticulously examining and confirming the feasibility of attacks initiated from both server and client sides, along with the underlying assumptions. Specifically, for attacks originating from the server, we propose the Model Approximation E stimation Reconstruction Attack (MAERA) to mitigate the requisite prior assumptions, and we also introduce the Distillation-based Client-side Reconstruction Attack (DCRA) to execute data reconstructions from the client for the first time. Experimental results illustrate the effectiveness and the robustness of the proposed frameworks in launching attacks across various datasets. In particular, MAERA necessitates merely 1% of the test set samples and 1% of the private data samples from the CIFAR100 dataset to unleash effective attacks, while DCRA adeptly expropriates models from clients and yields more pronounced reconstruction effects on target class samples during the process of inferring data distribution characteristics, in contrast to conventional Maximum A Posteriori (MAP) estimation algorithms.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] GaN-based devices
    Shur, MS
    2005 SPANISH CONFERENCE ON ELECTRON DEVICES, PROCEEDINGS, 2005, : 15 - 18
  • [42] GaN-based electronics
    Kuzuhara, Masaaki
    NINTH INTERNATIONAL CONFERENCE ON ADVANCED SEMICONDUCTOR DEVICES AND MICROSYSTEMS, 2012, : 1 - 6
  • [43] Structural defects in GaN-based materials and their relation to GaN-based laser diodes
    Tomiya, S.
    Ikeda, M.
    Tanaka, S.
    Kanitani, Y.
    Ohkubo, T.
    Hono, K.
    RELIABILITY AND MATERIALS ISSUES OF SEMICONDUCTOR OPTICAL AND ELECTRICAL DEVICES AND MATERIALS, 2010, 1195
  • [44] GAN-based deep neural networks for graph representation learning
    Zhao, Ming
    Zhang, Yinglong
    ENGINEERING REPORTS, 2022, 4 (11)
  • [45] GAN-Based Information Leakage Attack Detection in Federated Learning
    Lai, Jianxiong
    Huang, Xiuli
    Gao, Xianzhou
    Xia, Chang
    Hua, Jingyu
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [46] GAN-Based Dual Active Learning for Nosocomial Infection Detection
    Wang, Li
    Ye, Xin
    Li, Jialin
    Wen, Yu
    Liao, Wenbin
    Song, Houbing
    Chen, Jie
    Li, Jianqiang
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2022, 9 (05): : 3282 - 3291
  • [47] Empowering Predictive Modeling by GAN-based Causal Information Learning
    Zeng, Jinwei
    Zhang, Guozhen
    Yuan, Jian
    Li, Yong
    Jin, Depeng
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2024, 15 (03)
  • [48] GRL: Knowledge graph completion with GAN-based reinforcement learning
    Wang, Qi
    Ji, Yuede
    Hao, Yongsheng
    Cao, Jie
    KNOWLEDGE-BASED SYSTEMS, 2020, 209
  • [49] GAN-based Intrinsic Exploration for Sample Efficient Reinforcement Learning
    Kamar, Dogay
    Ure, Nazim Kemal
    Unal, Gozde
    ICAART: PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON AGENTS AND ARTIFICIAL INTELLIGENCE - VOL 2, 2022, : 264 - 272
  • [50] Heterogeneous Ensemble Federated Learning With GAN-Based Privacy Preservation
    Chen, Meng
    Liu, Hengzhu
    Chi, Huanhuan
    Xiong, Ping
    IEEE TRANSACTIONS ON SUSTAINABLE COMPUTING, 2024, 9 (04): : 591 - 601