Hiding in Plain Sight: Disguising Data Stealing Attacks in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Garov, Kostadin, Dimitrov, Dimitar I., Jovanović, Nikola, Vechev, Martin
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910410489200640
author Garov, Kostadin
Dimitrov, Dimitar I.
Jovanović, Nikola
Vechev, Martin
author_facet Garov, Kostadin
Dimitrov, Dimitar I.
Jovanović, Nikola
Vechev, Martin
contents Malicious server (MS) attacks have enabled the scaling of data stealing in federated learning to large batch sizes and secure aggregation, settings previously considered private. However, many concerns regarding the client-side detectability of MS attacks were raised, questioning their practicality. In this work, for the first time, we thoroughly study client-side detectability. We first demonstrate that all prior MS attacks are detectable by principled checks, and formulate a necessary set of requirements that a practical MS attack must satisfy. Next, we propose SEER, a novel attack framework that satisfies these requirements. The key insight of SEER is the use of a secret decoder, jointly trained with the shared model. We show that SEER can steal user data from gradients of realistic networks, even for large batch sizes of up to 512 and under secure aggregation. Our work is a promising step towards assessing the true vulnerability of federated learning in real-world settings.
format Preprint
id arxiv_https___arxiv_org_abs_2306_03013
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Hiding in Plain Sight: Disguising Data Stealing Attacks in Federated Learning
Garov, Kostadin
Dimitrov, Dimitar I.
Jovanović, Nikola
Vechev, Martin
Cryptography and Security
Machine Learning
I.2.11
Malicious server (MS) attacks have enabled the scaling of data stealing in federated learning to large batch sizes and secure aggregation, settings previously considered private. However, many concerns regarding the client-side detectability of MS attacks were raised, questioning their practicality. In this work, for the first time, we thoroughly study client-side detectability. We first demonstrate that all prior MS attacks are detectable by principled checks, and formulate a necessary set of requirements that a practical MS attack must satisfy. Next, we propose SEER, a novel attack framework that satisfies these requirements. The key insight of SEER is the use of a secret decoder, jointly trained with the shared model. We show that SEER can steal user data from gradients of realistic networks, even for large batch sizes of up to 512 and under secure aggregation. Our work is a promising step towards assessing the true vulnerability of federated learning in real-world settings.
title Hiding in Plain Sight: Disguising Data Stealing Attacks in Federated Learning
topic Cryptography and Security
Machine Learning
I.2.11
url https://arxiv.org/abs/2306.03013