A More Secure Split: Enhancing the Security of Privacy-Preserving Split Learning

被引:0
|
作者
Khan, Tanveer [1 ]
Nguyen, Khoa [1 ]
Michalas, Antonis [1 ,2 ]
机构
[1] Tampere Univ, Tampere, Finland
[2] RISE Res Inst Sweden, Gothenburg, Sweden
来源
关键词
Activation Maps; Homomorphic Encryption; Machine Learning; Privacy; Split Learning;
D O I
10.1007/978-3-031-47748-5_17
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Split learning (SL) is a new collaborative learning technique that allows participants, e.g. a client and a server, to train machine learning models without the client sharing raw data. In this setting, the client initially applies its part of the machine learning model on the raw data to generate Activation Maps (AMs) and then sends them to the server to continue the training process. Previous works in the field demonstrated that reconstructing AMs could result in privacy leakage of client data. In addition to that, existing mitigation techniques that overcome the privacy leakage of SL prove to be significantly worse in terms of accuracy. In this paper, we improve upon previous works by constructing a protocol based on U-shaped SL that can operate on homomorphically encrypted data. More precisely, in our approach, the client applies homomorphic encryption on the AMs before sending them to the server, thus protecting user privacy. This is an important improvement that reduces privacy leakage in comparison to other SL-based works. Finally, our results show that, with the optimum set of parameters, training with HE data in the U-shaped SL setting only reduces accuracy by 2.65% compared to training on plaintext. In addition, raw training data privacy is preserved.
引用
收藏
页码:307 / 329
页数:23
相关论文
共 50 条
  • [31] TAPFed: Threshold Secure Aggregation for Privacy-Preserving Federated Learning
    Xu, Runhua
    Li, Bo
    Li, Chao
    Joshi, James B. D.
    Ma, Shuai
    Li, Jianxin
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4309 - 4323
  • [32] SVFGNN: A privacy-preserving vertical federated graph neural network model training framework based on split learning
    Liu, Yanjun
    Li, Hongwei
    Hao, Meng
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (01) : 261 - 283
  • [33] FedSIS: Federated Split Learning with Intermediate Representation Sampling for Privacy-preserving Generalized Face Presentation Attack Detection
    Alkhunaizi, Naif
    Srivatsan, Koushik
    Almalik, Faris
    Almakky, Ibrahim
    Nandakumar, Karthik
    2023 IEEE INTERNATIONAL JOINT CONFERENCE ON BIOMETRICS, IJCB, 2023,
  • [34] PPSTSL: A Privacy-preserving Dynamic Spatio-temporal Graph Data Federated Split Learning for traffic forecasting
    Feng, Yan
    Qian, Quan
    INFORMATION FUSION, 2025, 121
  • [35] SVFGNN: A privacy-preserving vertical federated graph neural network model training framework based on split learning
    Yanjun Liu
    Hongwei Li
    Meng Hao
    Peer-to-Peer Networking and Applications, 2024, 17 : 246 - 260
  • [36] Efficient Vanilla Split Learning for Privacy-Preserving Collaboration in Resource-Constrained Cyber-Physical Systems
    Azeri, Nabila
    Hioual, Ouided
    Hioual, Ouassila
    Informatica (Slovenia), 2024, 48 (11): : 167 - 180
  • [37] Enhancing Privacy-Preserving Intrusion Detection through Federated Learning
    Alazab, Ammar
    Khraisat, Ansam
    Singh, Sarabjot
    Jan, Tony
    ELECTRONICS, 2023, 12 (16)
  • [38] On the Security of Learnable Image Encryption for Privacy-Preserving Deep Learning
    Maung, April Pyone Maung
    Echizen, Isao
    Kiya, Hitoshi
    IEEE ACCESS, 2024, 12 : 126415 - 126425
  • [39] A security-friendly privacy-preserving solution for federated learning
    Karakoc, Ferhat
    Karacay, Leyli
    De Cnudde, Pinar comak
    Gulen, Utku
    Fuladi, Ramin
    Soykan, Elif Ustundag
    COMPUTER COMMUNICATIONS, 2023, 207 : 27 - 35
  • [40] U-shaped Vertical Split Learning with Local Differential Privacy for Privacy Preserving
    Wang, Liang
    Chen, Hao
    Zuo, Lina
    Liu, Haibo
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IX, ICIC 2024, 2024, 14870 : 72 - 81