Bài viết

Tấn công dịch ngược mô hình khuếch đại lên quá trình học liên kết

Từ khóaHọc liên kếttấn công dịch ngượcbảo mật vi saimã hóa đồng cấu

Tóm tắt

Học liên kết (Federated Learning - FL) cho phép huấn luyện mô hình chung mà vẫn bảo vệ quyền riêng tư của dữ liệu, đặc biệt phù hợp trong các lĩnh vực nhạy cảm như tài chính, giáo dục và y tế. Tuy nhiên, mặc dù có nhiều tiềm năng, FL vẫn đối mặt với nguy cơ bị xâm phạm quyền riêng tư, đặc biệt thông qua các tấn công dịch ngược gradient, cho phép khôi phục dữ liệu riêng tư từ các cập nhật mô hình được chia sẻ. Nghiên cứu này giới thiệu chiến lược khuếch đại phi tuyến, nhằm tăng cường hiệu quả của các tấn công này, từ đó làm nổi bật rủi ro rò rỉ dữ liệu trong môi trường FL. Bên cạnh đó, nhóm tác giả đã đánh giá khả năng chống chịu của một số cơ chế bảo vệ quyền riêng tư, như Bảo mật vi sai (Differential Privacy - DP) và Mã hóa đồng cấu (Homomorphic Encryption - HE), thông qua hai chỉ số được đề xuất là AvgSSIM và AvgMSE, để đo lường mức độ nghiêm trọng của các cuộc tấn công cũng như hiệu quả của các biện pháp phòng thủ.

Lượt tải theo tháng

0163212/2402/2503/2504/2505/2506/2507/2508/2509/2510/2511/2512/2501/2602/2603/2604/2605/26

Di chuột vào cột để xem số lượt tải.

Cách trích dẫn

Trần Anh Tú, Đinh Công Thành, Trần Đức Sự (2024). Tấn công dịch ngược mô hình khuếch đại lên quá trình học liên kết. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 3(23), 15-26. https://doi.org/10.54654/isj.v3i23.1066

Tài liệu tham khảo

  1. 1.Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang, “Deep learning with differential privacy”, Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp. 308–318, 2016.
  2. 2.Alham Fikri Aji and Kenneth Heafield, “Sparse communication for distributed gradient descent”, arXiv preprint arXiv:1704.05021, 2017.
  3. 3.Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et al, “Privacy-preserving deep learning via additively homomorphic encryption”, IEEE transactions on information forensics and security, 13(5):1333–1345, 2017.
  4. 4.Jeremy Bernstein, Yu-Xiang Wang, Kamyar Azizzadenesheli, and Animashree Anandkumar, “Compressed optimisation for non-convex problems”, International Conference on Machine Learning, pp. 560–569. PMLR, 2018.
  5. 5.Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth, “Practical secure aggregation for federated learning on user-held data”, arXiv preprint arXiv:1611.04482, 2016.
  6. 6.Si Chen, Mostafa Kahla, Ruoxi Jia, and GuoJun Qi, “Knowledge-enriched distributional model inversion attacks”, Proceedings of the IEEE/CVF international conference on computer vision,
  7. 7.pp. 16178–16187, 2021.
  8. 8.Jinhao Duan, Fei Kong, Shiqi Wang, Xiaoshuang Shi, and Kaidi Xu, “Are diffusion models vulnerable to membership inference attacks?”, International Conference on Machine Learning, pp. 8717–8730. PMLR, 2023.
  9. 9.Matt Fredrikson, Somesh Jha, and Thomas Ristenpart, “Model inversion attacks that
  10. 10.exploit confidence information and basic countermeasures”, Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, pp. 1322– 1333, 2015.
  11. 11.Jonas Geiping, Hartmut Bauermeister, Hannah Droge, and Michael Moeller, “Inverting gradientshow easy is it to break privacy in federated learning?”, Advances in neural information processing systems, pp. 33:16937-16947, 2020.
  12. 12.Briland Hitaj, Giuseppe Ateniese, and Fernando Perez-Cruz, “Deep models under the gan: information leakage from collaborative deep learning”, Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp. 603-618, 2017.
  13. 13.Jinwoo Jeon, Kangwook Lee, Sewoong Oh, Jungseul Ok, et al, “Gradient inversion with generative image prior”, Advances in neural information processing systems, pp. 34:29898–29908, 2021.
  14. 14.Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas, “Communication-efficient learning of deep networks from decentralized data”, Artificial intelligence and statistics, pp. 1273–1282. PMLR, 2017.
  15. 15.Ahmed Salem, Apratim Bhattacharya, Michael Backes, Mario Fritz, and Yang Zhang, {UpdatesLeak}: “Data set inference and reconstruction attacks in online learning”, 29th USENIX security symposium (USENIX Security 20), pp. 1291–1308, 2020.
  16. 16.T. A. Tu, L. T. Dung, and P. X. Sang, “A novel privacy-preserving federated learning model based on secure multi-party computation”, International Symposium on Integrated Uncertainty in Knowledge Modelling and Decision Making, pp. 321–333. Springer, 2023.
  17. 17.Ziqi Yang, Jiyi Zhang, Ee-Chien Chang, and Zhenkai Liang, “Neural network inversion in adversarial setting via background knowledge alignment”, Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 225–240, 2019.
  18. 18.Hongxu Yin, Arun Mallya, Arash Vahdat, Jose M Alvarez, Jan Kautz, and Pavlo Molchanov, “See through gradients: Image batch recovery via gradinversion”, Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, pp. 16337–16346, 2021.
  19. 19.Yuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang, Bo Li, and Dawn Song, “The secret revealer: Generative model-inversion attacks against deep neural networks”, Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, pp. 253-261, 2020.
  20. 20.Zeping Zhang, Xiaowen Wang, Jie Huang, and Shuaishuai Zhang, “Analysis and utilization of hidden information in model inversion attacks”, IEEE Transactions on Information Forensics and Security, vol. 18, pp.4449-4462, 2023.
  21. 21.Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen, “idlg: Improved deep leakage from gradients”, arXiv preprint arXiv:2001.02610, 2020.
  22. 22.Ligeng Zhu, Zhijian Liu, and Song Han, “Deep leakage from gradients”, Advances in neural information processing systems, no. 1323, pp. 14774 - 14784, 2019.

Bài viết liên quan

Tấn công dịch ngược mô hình khuếch đại lên quá trình học liên kết | Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin