Mitigation of Membership Inference Attack by Knowledge Distillation on Federated Learning

被引:0
|
作者
Ueda, Rei [1 ]
Nakai, Tsunato [2 ]
Yoshida, Kota [3 ]
Fujino, Takeshi [3 ]
机构
[1] Ritsumeikan Univ, Grad Sch Sci & Engn, Kusatsu 5258577, Japan
[2] Mitsubishi Electr Corp, Kamakura 2478501, Japan
[3] Ritsumeikan Univ, Dept Sci & Engn, Kusatsu 5258577, Japan
关键词
federated learning; knowledge distillation; membership inference attack;
D O I
10.1587/transfun.2024CIP0004
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning (FL) is a distributed deep learning technique involving multiple clients and a server. In FL, each client individually trains a model with its own training data and sends only the model to the server. The server then aggregates the received client models to build a server model. Because each client does not share its own training data with other clients or the server, FL is considered a distributed deep learning technique with privacy protection. However, several attacks that steal information about a specific client's training data from the aggregated model on the server have been reported for FL. These include membership inference attacks (MIAs), which identify whether or not specific data was used to train a target model. MIAs have been shown to work mainly because of over fitting of the model to the training data, and mitigation techniques based on knowledge distillation have thus been proposed. Because these techniques assume a lot of training data and computational power, they are difficult to introduce simply to clients in FL. In this paper, we propose a knowledge-distillation-based defense against MIAs that is designed for application in FL. The proposed method is effective against various MIAs without requiring additional training data, in contrast to the conventional defenses.
引用
收藏
页码:267 / 279
页数:13
相关论文
共 50 条
  • [1] Label-Only Membership Inference Attack Against Federated Distillation
    Wang, Xi
    Zhao, Yanchao
    Zhang, Jiale
    Chen, Bing
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT II, 2024, 14488 : 394 - 410
  • [2] MIA-BAD: An Approach for Enhancing Membership Inference Attack and its Mitigation with Federated Learning
    Banerjee, Soumya
    Roy, Sandip
    Ahamed, Sayyed Farid
    Quinn, Devin
    Vucovich, Marc
    Nandakumar, Dhruv
    Choi, Kevin
    Rahman, Abdul
    Bowen, Edward
    Shetty, Sachin
    2024 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2024, : 635 - 640
  • [3] GBMIA: Gradient-based Membership Inference Attack in Federated Learning
    Wang, Xiaodong
    Wang, Naiyu
    Wu, Longfei
    Guan, Zhitao
    Du, Xiaojiang
    Guizani, Mohsen
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 5066 - 5071
  • [4] Membership inference attack and defense method in federated learning based on GAN
    Zhang J.
    Zhu C.
    Sun X.
    Chen B.
    Tongxin Xuebao/Journal on Communications, 2023, 44 (05): : 193 - 205
  • [5] GAN Enhanced Membership Inference: A Passive Local Attack in Federated Learning
    Zhang, Jingwen
    Zhang, Jiale
    Chen, Junjun
    Yu, Shui
    ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [6] FD-Leaks: Membership Inference Attacks Against Federated Distillation Learning
    Yang, Zilu
    Zhao, Yanchao
    Zhang, Jiale
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 364 - 378
  • [7] Active Membership Inference Attack under Local Differential Privacy in Federated Learning
    Nguyen, Truc
    Lai, Phung
    Tran, Khang
    Phan, NhatHai
    Thai, My T.
    INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS, VOL 206, 2023, 206
  • [8] Leveraging Multiple Adversarial Perturbation Distances for Enhanced Membership Inference Attack in Federated Learning
    Xia, Fan
    Liu, Yuhao
    Jin, Bo
    Yu, Zheng
    Cai, Xingwei
    Li, Hao
    Zha, Zhiyong
    Hou, Dai
    Peng, Kai
    SYMMETRY-BASEL, 2024, 16 (12):
  • [9] Enhance membership inference attacks in federated learning
    He, Xinlong
    Xu, Yang
    Zhang, Sicong
    Xu, Weida
    Yan, Jiale
    COMPUTERS & SECURITY, 2024, 136
  • [10] Defending Against Membership Inference Attack for Counterfactual Federated Recommendation With Differentially Private Representation Learning
    Liu, Xiuwen
    Chen, Yanjiao
    Pang, Shanchen
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 8037 - 8051