Passive Inference Attacks on Split Learning via Adversarial Regularization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhu, Xiaochen, Luo, Xinjian, Wu, Yuncheng, Jiang, Yangfan, Xiao, Xiaokui, Ooi, Beng Chin
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912286548951040
author Zhu, Xiaochen
Luo, Xinjian
Wu, Yuncheng
Jiang, Yangfan
Xiao, Xiaokui
Ooi, Beng Chin
author_facet Zhu, Xiaochen
Luo, Xinjian
Wu, Yuncheng
Jiang, Yangfan
Xiao, Xiaokui
Ooi, Beng Chin
contents Split Learning (SL) has emerged as a practical and efficient alternative to traditional federated learning. While previous attempts to attack SL have often relied on overly strong assumptions or targeted easily exploitable models, we seek to develop more capable attacks. We introduce SDAR, a novel attack framework against SL with an honest-but-curious server. SDAR leverages auxiliary data and adversarial regularization to learn a decodable simulator of the client's private model, which can effectively infer the client's private features under the vanilla SL, and both features and labels under the U-shaped SL. We perform extensive experiments in both configurations to validate the effectiveness of our proposed attacks. Notably, in challenging scenarios where existing passive attacks struggle to reconstruct the client's private data effectively, SDAR consistently achieves significantly superior attack performance, even comparable to active attacks. On CIFAR-10, at the deep split level of 7, SDAR achieves private feature reconstruction with less than 0.025 mean squared error in both the vanilla and the U-shaped SL, and attains a label inference accuracy of over 98% in the U-shaped setting, while existing attacks fail to produce non-trivial results.
format Preprint
id arxiv_https___arxiv_org_abs_2310_10483
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Passive Inference Attacks on Split Learning via Adversarial Regularization
Zhu, Xiaochen
Luo, Xinjian
Wu, Yuncheng
Jiang, Yangfan
Xiao, Xiaokui
Ooi, Beng Chin
Cryptography and Security
Machine Learning
Split Learning (SL) has emerged as a practical and efficient alternative to traditional federated learning. While previous attempts to attack SL have often relied on overly strong assumptions or targeted easily exploitable models, we seek to develop more capable attacks. We introduce SDAR, a novel attack framework against SL with an honest-but-curious server. SDAR leverages auxiliary data and adversarial regularization to learn a decodable simulator of the client's private model, which can effectively infer the client's private features under the vanilla SL, and both features and labels under the U-shaped SL. We perform extensive experiments in both configurations to validate the effectiveness of our proposed attacks. Notably, in challenging scenarios where existing passive attacks struggle to reconstruct the client's private data effectively, SDAR consistently achieves significantly superior attack performance, even comparable to active attacks. On CIFAR-10, at the deep split level of 7, SDAR achieves private feature reconstruction with less than 0.025 mean squared error in both the vanilla and the U-shaped SL, and attains a label inference accuracy of over 98% in the U-shaped setting, while existing attacks fail to produce non-trivial results.
title Passive Inference Attacks on Split Learning via Adversarial Regularization
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2310.10483