Approximate and Weighted Data Reconstruction Attack in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Song, Yongcun, Wang, Ziqi, Zuazua, Enrique
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911686352437248
author Song, Yongcun
Wang, Ziqi
Zuazua, Enrique
author_facet Song, Yongcun
Wang, Ziqi
Zuazua, Enrique
contents Federated Learning (FL) is a distributed learning paradigm that enables multiple clients to collaborate on building a machine learning model without sharing their private data. Although FL is considered privacy-preserved by design, recent data reconstruction attacks demonstrate that an attacker can recover clients' training data based on the parameters shared in FL. However, most existing methods fail to attack the most widely used horizontal Federated Averaging (FedAvg) scenario, where clients share model parameters after multiple local training steps. To tackle this issue, we propose an interpolation-based approximation method, which makes attacking FedAvg scenarios feasible by generating the intermediate model updates of the clients' local training processes. Then, we design a layer-wise weighted loss function to improve the data quality of reconstruction. We assign different weights to model updates in different layers concerning the neural network structure, with the weights tuned by Bayesian optimization. Finally, experimental results validate the superiority of our proposed approximate and weighted attack (AWA) method over the other state-of-the-art methods, as demonstrated by the substantial improvement in different evaluation metrics for image data reconstructions.
format Preprint
id arxiv_https___arxiv_org_abs_2308_06822
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Approximate and Weighted Data Reconstruction Attack in Federated Learning
Song, Yongcun
Wang, Ziqi
Zuazua, Enrique
Machine Learning
Artificial Intelligence
Cryptography and Security
Optimization and Control
Federated Learning (FL) is a distributed learning paradigm that enables multiple clients to collaborate on building a machine learning model without sharing their private data. Although FL is considered privacy-preserved by design, recent data reconstruction attacks demonstrate that an attacker can recover clients' training data based on the parameters shared in FL. However, most existing methods fail to attack the most widely used horizontal Federated Averaging (FedAvg) scenario, where clients share model parameters after multiple local training steps. To tackle this issue, we propose an interpolation-based approximation method, which makes attacking FedAvg scenarios feasible by generating the intermediate model updates of the clients' local training processes. Then, we design a layer-wise weighted loss function to improve the data quality of reconstruction. We assign different weights to model updates in different layers concerning the neural network structure, with the weights tuned by Bayesian optimization. Finally, experimental results validate the superiority of our proposed approximate and weighted attack (AWA) method over the other state-of-the-art methods, as demonstrated by the substantial improvement in different evaluation metrics for image data reconstructions.
title Approximate and Weighted Data Reconstruction Attack in Federated Learning
topic Machine Learning
Artificial Intelligence
Cryptography and Security
Optimization and Control
url https://arxiv.org/abs/2308.06822