Turning Privacy-preserving Mechanisms against Federated Learning

被引:5
|
作者
Arazzi, Marco [1 ]
Conti, Mauro [2 ,3 ]
Nocera, Antonino [1 ]
Picek, Stjepan [3 ,4 ]
机构
[1] Univ Pavia, Pavia, Italy
[2] Univ Padua, Padua, Italy
[3] Delft Univ Technol, Delft, Netherlands
[4] Radboud Univ Nijmegen, Nijmegen, Netherlands
关键词
Federated Learning; Graph Neural Network; Model Poisoning; Privacy; Recommender Systems;
D O I
10.1145/3576915.3623114
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, researchers have successfully employed Graph Neural Networks (GNNs) to build enhanced recommender systems due to their capability to learn patterns from the interaction between involved entities. In addition, previous studies have investigated federated learning as the main solution to enable a native privacy-preserving mechanism for the construction of global GNN models without collecting sensitive data into a single computation unit. Still, privacy issues may arise as the analysis of local model updates produced by the federated clients can return information related to sensitive local data. For this reason, researchers proposed solutions that combine federated learning with Differential Privacy strategies and community-driven approaches, which involve combining data from neighbor clients to make the individual local updates less dependent on local sensitive data. In this paper, we identify a crucial security flaw in such a configuration and design an attack capable of deceiving state-of-the-art defenses for federated learning. The proposed attack includes two operating modes, the first one focusing on convergence inhibition (Adversarial Mode), and the second one aiming at building a deceptive rating injection on the global federated model (Backdoor Mode). The experimental results show the effectiveness of our attack in both its modes, returning on average 60% performance detriment in all the tests on Adversarial Mode and fully effective backdoors in 93% of cases for the tests performed on Backdoor Mode.
引用
收藏
页码:1482 / 1495
页数:14
相关论文
共 50 条
  • [41] PASTEL: Privacy-Preserving Federated Learning in Edge Computing
    Elhattab, Fatima
    Bouchenak, Sara
    Boscher, Cedric
    PROCEEDINGS OF THE ACM ON INTERACTIVE MOBILE WEARABLE AND UBIQUITOUS TECHNOLOGIES-IMWUT, 2023, 7 (04):
  • [42] PVFL: Verifiable federated learning and prediction with privacy-preserving
    Yin, Benxin
    Zhang, Hanlin
    Lin, Jie
    Kong, Fanyu
    Yu, Leyun
    COMPUTERS & SECURITY, 2024, 139
  • [43] Visual Object Detection for Privacy-Preserving Federated Learning
    Zhang, Jing
    Zhou, Jiting
    Guo, Jinyang
    Sun, Xiaohan
    IEEE ACCESS, 2023, 11 : 33324 - 33335
  • [44] Enforcing group fairness in privacy-preserving Federated Learning
    Chen, Chaomeng
    Zhou, Zhenhong
    Tang, Peng
    He, Longzhu
    Su, Sen
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 160 : 890 - 900
  • [45] Towards Efficient and Privacy-preserving Federated Deep Learning
    Hao, Meng
    Li, Hongwei
    Xu, Guowen
    Liu, Sen
    Yang, Haomiao
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [46] Federated Learning for Privacy-Preserving Machine Learning in IoT Networks
    Anitha, G.
    Jegatheesan, A.
    2024 SECOND INTERNATIONAL CONFERENCE ON INTELLIGENT CYBER PHYSICAL SYSTEMS AND INTERNET OF THINGS, ICOICI 2024, 2024, : 338 - 342
  • [47] DER Forecast Using Privacy-Preserving Federated Learning
    Venkataramanan, Venkatesh
    Kaza, Sridevi
    Annaswamy, Anuradha M.
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (03) : 2046 - 2055
  • [48] Decentralized federated learning with privacy-preserving for recommendation systems
    Guo, Jianlan
    Zhao, Qinglin
    Li, Guangcheng
    Chen, Yuqiang
    Lao, Chengxue
    Feng, Li
    ENTERPRISE INFORMATION SYSTEMS, 2023, 17 (09)
  • [49] Local Model Privacy-Preserving Study for Federated Learning
    Pan, Kaiyun
    He, Daojing
    Xu, Chuan
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2021, PT I, 2021, 398 : 287 - 307
  • [50] Privacy-Preserving Heterogeneous Personalized Federated Learning With Knowledge
    Pan, Yanghe
    Su, Zhou
    Ni, Jianbing
    Wang, Yuntao
    Zhou, Jinhao
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2024, 11 (06): : 5969 - 5982