Label Inference Attacks against Federated Unlearning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Wei, Tang, Xiangyun, Wang, Yajie, Lin, Yijing, Zhang, Tao, Shen, Meng, Niyato, Dusit, Zhu, Liehuang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909730886123520
author Wang, Wei
Tang, Xiangyun
Wang, Yajie
Lin, Yijing
Zhang, Tao
Shen, Meng
Niyato, Dusit
Zhu, Liehuang
author_facet Wang, Wei
Tang, Xiangyun
Wang, Yajie
Lin, Yijing
Zhang, Tao
Shen, Meng
Niyato, Dusit
Zhu, Liehuang
contents Federated Unlearning (FU) has emerged as a promising solution to respond to the right to be forgotten of clients, by allowing clients to erase their data from global models without compromising model performance. Unfortunately, researchers find that the parameter variations of models induced by FU expose clients' data information, enabling attackers to infer the label of unlearning data, while label inference attacks against FU remain unexplored. In this paper, we introduce and analyze a new privacy threat against FU and propose a novel label inference attack, ULIA, which can infer unlearning data labels across three FU levels. To address the unique challenges of inferring labels via the models variations, we design a gradient-label mapping mechanism in ULIA that establishes a relationship between gradient variations and unlearning labels, enabling inferring labels on accumulated model variations. We evaluate ULIA on both IID and non-IID settings. Experimental results show that in the IID setting, ULIA achieves a 100% Attack Success Rate (ASR) under both class-level and client-level unlearning. Even when only 1% of a user's local data is forgotten, ULIA still attains an ASR ranging from 93% to 62.3%.
format Preprint
id arxiv_https___arxiv_org_abs_2508_06789
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Label Inference Attacks against Federated Unlearning
Wang, Wei
Tang, Xiangyun
Wang, Yajie
Lin, Yijing
Zhang, Tao
Shen, Meng
Niyato, Dusit
Zhu, Liehuang
Cryptography and Security
Federated Unlearning (FU) has emerged as a promising solution to respond to the right to be forgotten of clients, by allowing clients to erase their data from global models without compromising model performance. Unfortunately, researchers find that the parameter variations of models induced by FU expose clients' data information, enabling attackers to infer the label of unlearning data, while label inference attacks against FU remain unexplored. In this paper, we introduce and analyze a new privacy threat against FU and propose a novel label inference attack, ULIA, which can infer unlearning data labels across three FU levels. To address the unique challenges of inferring labels via the models variations, we design a gradient-label mapping mechanism in ULIA that establishes a relationship between gradient variations and unlearning labels, enabling inferring labels on accumulated model variations. We evaluate ULIA on both IID and non-IID settings. Experimental results show that in the IID setting, ULIA achieves a 100% Attack Success Rate (ASR) under both class-level and client-level unlearning. Even when only 1% of a user's local data is forgotten, ULIA still attains an ASR ranging from 93% to 62.3%.
title Label Inference Attacks against Federated Unlearning
topic Cryptography and Security
url https://arxiv.org/abs/2508.06789