Efficient Membership Inference Attacks against Federated Learning via Bias Differences

被引:1
|
作者
Zhang, Liwei [1 ]
Li, Linghui [1 ]
Li, Xiaoyong [1 ]
Cai, Binsi [1 ]
Gao, Yali [1 ]
Dou, Ruobin [2 ]
Chen, Luying [3 ]
机构
[1] Beijing Univ Posts & Telecommun, Key Lab Trustworthy Distributed Comp & Serv MoE, Beijing, Peoples R China
[2] China Mobile Grp Tianjin Co Itd, Tianjin, Peoples R China
[3] HAOHAN Data Technol Co Ltd, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; membership inference attack; bias; PRIVACY;
D O I
10.1145/3607199.3607204
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning aims to complete model training without private data sharing, but many privacy risks remain. Recent studies have shown that federated learning is vulnerable to membership inference attacks. The weight as an important parameter in neural networks has been proven effective for membership inference attacks, but it leads to significant overhead. Facing this issue, in this paper, we propose a bias-based method for efficient membership inference attacks against federated learning. Different from the weight that determines the direction of the decision surface, the bias also plays an important role in determining the distance to move along the direction. Moreover, the number of bias is way less than the weight. We consider two types of attacks: local attack and global attack, corresponding to two possible types of insiders: participant and central aggregator. For the local attack, we design a neural network-based inference, which fully learns the vertical bias changes of the member data and non-member data. For the global attack, we design a difference comparison-based inference to determine the data source. Extensive experimental results on four public datasets show that the proposed method achieves state-of-the-art inference accuracy. Moreover, experiments prove the effectiveness of the proposed method to resist some commonly used defenses.
引用
收藏
页码:222 / 235
页数:14
相关论文
共 50 条
  • [41] FLSG: A Novel Defense Strategy Against Inference Attacks in Vertical Federated Learning
    Fan, Kai
    Hong, Jingtao
    Li, Wenjie
    Zhao, Xingwen
    Li, Hui
    Yang, Yintang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (02) : 1816 - 1826
  • [42] Membership Inference Attacks on Machine Learning: A Survey
    Hu, Hongsheng
    Salcic, Zoran
    Sun, Lichao
    Dobbie, Gillian
    Yu, Philip S.
    Zhang, Xuyun
    ACM COMPUTING SURVEYS, 2022, 54 (11S)
  • [43] Inference attacks based on GAN in federated learning
    Trung Ha
    Tran Khanh Dang
    INTERNATIONAL JOURNAL OF WEB INFORMATION SYSTEMS, 2022, 18 (2/3) : 117 - 136
  • [44] VAE-Based Membership Cleanser Against Membership Inference Attacks
    Hu, Li
    Yan, Hongyang
    Peng, Yun
    Hu, Haibo
    Wang, Shaowei
    Li, Jin
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 1253 - 1264
  • [45] Defending Against Membership Inference Attacks on Beacon Services
    Venkatesaramani, Rajagopal
    Wan, Zhiyu
    Malin, Bradley A.
    Vorobeychik, Yevgeniy
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (03)
  • [46] Membership Inference Attacks Against Semantic Segmentation Models
    Chobola, Tomas
    Usynin, Dmitrii
    Kaissis, Georgios
    PROCEEDINGS OF THE 16TH ACM WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, AISEC 2023, 2023, : 43 - 53
  • [47] Secure Aggregation Is Not Private Against Membership Inference Attacks
    Ngo, Khac-Hoang
    Ostman, Johan
    Durisi, Giuseppe
    Graell i Amat, Alexandre
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES-RESEARCH TRACK, PT VI, ECML PKDD 2024, 2024, 14946 : 180 - 198
  • [48] MiDA: Membership inference attacks against domain adaptation
    Zhang, Yuanjie
    Zhao, Lingchen
    Wang, Qian
    ISA TRANSACTIONS, 2023, 141 : 103 - 112
  • [49] Membership inference attacks against synthetic health data
    Zhang, Ziqi
    Yan, Chao
    Malin, Bradley A.
    JOURNAL OF BIOMEDICAL INFORMATICS, 2022, 125
  • [50] Semi-Leak: Membership Inference Attacks Against Semi-supervised Learning
    He, Xinlei
    Liu, Hongbin
    Gong, Neil Zhenqiang
    Zhang, Yang
    COMPUTER VISION, ECCV 2022, PT XXXI, 2022, 13691 : 365 - 381