计算机科学
信息隐私
过程(计算)
计算机安全
信息敏感性
桥(图论)
私人信息检索
反演(地质)
水准点(测量)
光学(聚焦)
差别隐私
数据科学
班级(哲学)
信息泄露
隐私保护
联合学习
数据建模
数据匿名化
大数据
设计隐私
数据挖掘
1998年数据保护法
人工智能
作者
Lei Zhou,Youwen Zhu,Rongke Liu
标识
DOI:10.1109/tifs.2026.3666295
摘要
In response to emerging regulations on the “right to be forgotten”, federated unlearning (FU) has been proposed to ensure privacy compliance by efficiently eliminating the influence of specific data from federated learning (FL) models. However, existing FU studies primarily focus on improving unlearning efficiency, with little attention given to the potential privacy risks introduced by FU itself. To bridge this research gap, we propose a novel federated unlearning inversion attack (FUIA) to expose potential privacy leakage in FU. This work represents the first systematic study on the privacy vulnerabilities inherent in FU. FUIA can apply to three major FU scenarios: sample unlearning, client unlearning, and class unlearning, demonstrating broad applicability and threat potential. Specifically, the server, acting as an honest-but-curious attacker, continuously records model parameter changes throughout the unlearning process and analyzes the differences before and after unlearning to infer the gradient information of forgotten data, enabling the reconstruction of its features or labels. FUIA directly undermines the goal of FU to eliminate the influence of specific data, exploiting vulnerabilities in the FU process to reconstruct forgotten data, thereby revealing flaws in privacy protection. Moreover, we explore two potential defense strategies that introduce a trade-off between privacy protection and model performance. Extensive experiments on multiple benchmark datasets and various FU methods demonstrate that FUIA effectively reveals private information of forgotten data.
科研通智能强力驱动
Strongly Powered by AbleSci AI