Eavesdrop the Composition Proportion of Training Labels in Federated Learning

10/14/2019
by   Lixu Wang, et al.
12

Federated learning (FL) has recently emerged as a new form of collaborative machine learning, where a common model can be learned while keeping all the training data on local devices. Although it is designed for enhancing the data privacy, we demonstrated in this paper a new direction in inference attacks in the context of FL, where valuable information about training data can be obtained by adversaries with very limited power. In particular, we proposed three new types of attacks to exploit this vulnerability. The first type of attack, Class Sniffing, can detect whether a certain label appears in training. The other two types of attacks can determine the quantity of each label, i.e., Quantity Inference attack determines the composition proportion of the training label owned by the selected clients in a single round, while Whole Determination attack determines that of the whole training process. We evaluated our attacks on a variety of tasks and datasets with different settings, and the corresponding results showed that our attacks work well generally. Finally, we analyzed the impact of major hyper-parameters to our attacks and discussed possible defenses.

READ FULL TEXT

page 4

page 5

page 10

research
06/06/2023

A Survey on Federated Learning Poisoning Attacks and Defenses

As one kind of distributed machine learning technique, federated learnin...
research
11/27/2022

Federated Learning Attacks and Defenses: A Survey

In terms of artificial intelligence, there are several security and priv...
research
08/14/2020

Towards Class Imbalance in Federated Learning

Federated learning (FL) is a promising approach for training decentraliz...
research
12/07/2020

Privacy and Robustness in Federated Learning: Attacks and Defenses

As data are increasingly being stored in different silos and societies b...
research
01/13/2022

Jamming Attacks on Federated Learning in Wireless Networks

Federated learning (FL) offers a decentralized learning environment so t...
research
04/18/2023

BadVFL: Backdoor Attacks in Vertical Federated Learning

Federated learning (FL) enables multiple parties to collaboratively trai...
research
12/26/2021

Attribute Inference Attack of Speech Emotion Recognition in Federated Learning Settings

Speech emotion recognition (SER) processes speech signals to detect and ...

Please sign up or login with your details

Forgot password? Click here to reset