Efficient Membership Inference Attacks against Federated Learning via Bias Differences

被引:0
|
作者
Zhang, Liwei [1 ]
Li, Linghui [1 ]
Li, Xiaoyong [1 ]
Cai, Binsi [1 ]
Gao, Yali [1 ]
Dou, Ruobin [2 ]
Chen, Luying [3 ]
机构
[1] Beijing Univ Posts & Telecommun, Key Lab Trustworthy Distributed Comp & Serv MoE, Beijing, Peoples R China
[2] China Mobile Grp Tianjin Co Itd, Tianjin, Peoples R China
[3] HAOHAN Data Technol Co Ltd, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; membership inference attack; bias; PRIVACY;
D O I
10.1145/3607199.3607204
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning aims to complete model training without private data sharing, but many privacy risks remain. Recent studies have shown that federated learning is vulnerable to membership inference attacks. The weight as an important parameter in neural networks has been proven effective for membership inference attacks, but it leads to significant overhead. Facing this issue, in this paper, we propose a bias-based method for efficient membership inference attacks against federated learning. Different from the weight that determines the direction of the decision surface, the bias also plays an important role in determining the distance to move along the direction. Moreover, the number of bias is way less than the weight. We consider two types of attacks: local attack and global attack, corresponding to two possible types of insiders: participant and central aggregator. For the local attack, we design a neural network-based inference, which fully learns the vertical bias changes of the member data and non-member data. For the global attack, we design a difference comparison-based inference to determine the data source. Extensive experimental results on four public datasets show that the proposed method achieves state-of-the-art inference accuracy. Moreover, experiments prove the effectiveness of the proposed method to resist some commonly used defenses.
引用
收藏
页码:222 / 235
页数:14
相关论文
共 50 条
  • [1] Defending against Membership Inference Attacks in Federated learning via Adversarial Example
    Xie, Yuanyuan
    Chen, Bing
    Zhang, Jiale
    Wu, Di
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 153 - 160
  • [2] Source Inference Attacks: Beyond Membership Inference Attacks in Federated Learning
    Hu, Hongsheng
    Zhang, Xuyun
    Salcic, Zoran
    Sun, Lichao
    Choo, Kim-Kwang Raymond
    Dobbie, Gillian
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3012 - 3029
  • [3] Enhance membership inference attacks in federated learning
    He, Xinlong
    Xu, Yang
    Zhang, Sicong
    Xu, Weida
    Yan, Jiale
    COMPUTERS & SECURITY, 2024, 136
  • [4] Fortifying Federated Learning against Membership Inference Attacks via Client-level Input Perturbation
    Yang, Yuchen
    Yuan, Haolin
    Hui, Bo
    Gong, Neil
    Fendley, Neil
    Burlina, Philippe
    Cao, Yinzhi
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, DSN, 2023, : 288 - 301
  • [5] FD-Leaks: Membership Inference Attacks Against Federated Distillation Learning
    Yang, Zilu
    Zhao, Yanchao
    Zhang, Jiale
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 364 - 378
  • [6] Comparative Analysis of Membership Inference Attacks in Federated and Centralized Learning
    Abbasi Tadi, Ali
    Dayal, Saroj
    Alhadidi, Dima
    Mohammed, Noman
    INFORMATION, 2023, 14 (11)
  • [7] LoDen: Making Every Client in Federated Learning a Defender Against the Poisoning Membership Inference Attacks
    Ma, Mengyao
    Zhang, Yanjun
    Chamikara, M. A. P.
    Zhang, Leo Yu
    Chhetri, Mohan Baruwal
    Bai, Guangdong
    PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 122 - 135
  • [8] TEAR: Exploring Temporal Evolution of Adversarial Robustness for Membership Inference Attacks Against Federated Learning
    Liu, Gaoyang
    Tian, Zehao
    Chen, Jian
    Wang, Chen
    Liu, Jiangchuan
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 4996 - 5010
  • [9] Efficient Privacy-Preserving Federated Learning Against Inference Attacks for IoT
    Miao, Yifeng
    Chen, Siguang
    2023 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, WCNC, 2023,
  • [10] Efficient Federated Matrix Factorization Against Inference Attacks
    Chai, Di
    Wang, Leye
    Chen, Kai
    Yang, Qiang
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2022, 13 (04)