Just a Simple Transformation is Enough for Data Protection in Vertical Federated Learning
Fuente:
arXiv
Saved in:
| Main Authors: | , , , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866909430541451264 |
|---|---|
| author | Semenov, Andrei Zmushko, Philip Pichugin, Alexander Beznosikov, Aleksandr |
| author_facet | Semenov, Andrei Zmushko, Philip Pichugin, Alexander Beznosikov, Aleksandr |
| contents | Vertical Federated Learning (VFL) aims to enable collaborative training of deep learning models while maintaining privacy protection. However, the VFL procedure still has components that are vulnerable to attacks by malicious parties. In our work, we consider feature reconstruction attacks, a common risk targeting input data compromise. We theoretically claim that feature reconstruction attacks cannot succeed without knowledge of the prior distribution on data. Consequently, we demonstrate that even simple model architecture transformations can significantly impact the protection of input data during VFL. Confirming these findings with experimental results, we show that MLP-based models are resistant to state-of-the-art feature reconstruction attacks. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2412_11689 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Just a Simple Transformation is Enough for Data Protection in Vertical Federated Learning Semenov, Andrei Zmushko, Philip Pichugin, Alexander Beznosikov, Aleksandr Machine Learning Cryptography and Security I.2.m; F.2.0 Vertical Federated Learning (VFL) aims to enable collaborative training of deep learning models while maintaining privacy protection. However, the VFL procedure still has components that are vulnerable to attacks by malicious parties. In our work, we consider feature reconstruction attacks, a common risk targeting input data compromise. We theoretically claim that feature reconstruction attacks cannot succeed without knowledge of the prior distribution on data. Consequently, we demonstrate that even simple model architecture transformations can significantly impact the protection of input data during VFL. Confirming these findings with experimental results, we show that MLP-based models are resistant to state-of-the-art feature reconstruction attacks. |
| title | Just a Simple Transformation is Enough for Data Protection in Vertical Federated Learning |
| topic | Machine Learning Cryptography and Security I.2.m; F.2.0 |
| url | https://arxiv.org/abs/2412.11689 |