Quantifying and Defending against Privacy Threats on Federated Knowledge Graph Embedding

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Hu, Yuke, Liang, Wei, Wu, Ruofan, Xiao, Kai, Wang, Weiqiang, Li, Xiaochen, Liu, Jinfei, Qin, Zhan
Format: Preprint
Publié: 2023
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866913682049466368
author Hu, Yuke
Liang, Wei
Wu, Ruofan
Xiao, Kai
Wang, Weiqiang
Li, Xiaochen
Liu, Jinfei
Qin, Zhan
author_facet Hu, Yuke
Liang, Wei
Wu, Ruofan
Xiao, Kai
Wang, Weiqiang
Li, Xiaochen
Liu, Jinfei
Qin, Zhan
contents Knowledge Graph Embedding (KGE) is a fundamental technique that extracts expressive representation from knowledge graph (KG) to facilitate diverse downstream tasks. The emerging federated KGE (FKGE) collaboratively trains from distributed KGs held among clients while avoiding exchanging clients' sensitive raw KGs, which can still suffer from privacy threats as evidenced in other federated model trainings (e.g., neural networks). However, quantifying and defending against such privacy threats remain unexplored for FKGE which possesses unique properties not shared by previously studied models. In this paper, we conduct the first holistic study of the privacy threat on FKGE from both attack and defense perspectives. For the attack, we quantify the privacy threat by proposing three new inference attacks, which reveal substantial privacy risk by successfully inferring the existence of the KG triple from victim clients. For the defense, we propose DP-Flames, a novel differentially private FKGE with private selection, which offers a better privacy-utility tradeoff by exploiting the entity-binding sparse gradient property of FKGE and comes with a tight privacy accountant by incorporating the state-of-the-art private selection technique. We further propose an adaptive privacy budget allocation policy to dynamically adjust defense magnitude across the training procedure. Comprehensive evaluations demonstrate that the proposed defense can successfully mitigate the privacy threat by effectively reducing the success rate of inference attacks from $83.1\%$ to $59.4\%$ on average with only a modest utility decrease.
format Preprint
id arxiv_https___arxiv_org_abs_2304_02932
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Quantifying and Defending against Privacy Threats on Federated Knowledge Graph Embedding
Hu, Yuke
Liang, Wei
Wu, Ruofan
Xiao, Kai
Wang, Weiqiang
Li, Xiaochen
Liu, Jinfei
Qin, Zhan
Cryptography and Security
Artificial Intelligence
Knowledge Graph Embedding (KGE) is a fundamental technique that extracts expressive representation from knowledge graph (KG) to facilitate diverse downstream tasks. The emerging federated KGE (FKGE) collaboratively trains from distributed KGs held among clients while avoiding exchanging clients' sensitive raw KGs, which can still suffer from privacy threats as evidenced in other federated model trainings (e.g., neural networks). However, quantifying and defending against such privacy threats remain unexplored for FKGE which possesses unique properties not shared by previously studied models. In this paper, we conduct the first holistic study of the privacy threat on FKGE from both attack and defense perspectives. For the attack, we quantify the privacy threat by proposing three new inference attacks, which reveal substantial privacy risk by successfully inferring the existence of the KG triple from victim clients. For the defense, we propose DP-Flames, a novel differentially private FKGE with private selection, which offers a better privacy-utility tradeoff by exploiting the entity-binding sparse gradient property of FKGE and comes with a tight privacy accountant by incorporating the state-of-the-art private selection technique. We further propose an adaptive privacy budget allocation policy to dynamically adjust defense magnitude across the training procedure. Comprehensive evaluations demonstrate that the proposed defense can successfully mitigate the privacy threat by effectively reducing the success rate of inference attacks from $83.1\%$ to $59.4\%$ on average with only a modest utility decrease.
title Quantifying and Defending against Privacy Threats on Federated Knowledge Graph Embedding
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2304.02932