Turning Privacy-preserving Mechanisms against Federated Learning

后门 计算机科学 差别隐私 对抗制 联合学习 模式(计算机接口) 信息敏感性 计算机安全 方案(数学) 推荐系统 机器学习 人工智能 数据挖掘 人机交互 数学 数学分析
作者
Marco Arazzi,Mauro Conti,Antonino Nocera,Stjepan Picek
出处
期刊:Cornell University - arXiv 被引量:1
标识
DOI:10.48550/arxiv.2305.05355
摘要

Recently, researchers have successfully employed Graph Neural Networks (GNNs) to build enhanced recommender systems due to their capability to learn patterns from the interaction between involved entities. In addition, previous studies have investigated federated learning as the main solution to enable a native privacy-preserving mechanism for the construction of global GNN models without collecting sensitive data into a single computation unit. Still, privacy issues may arise as the analysis of local model updates produced by the federated clients can return information related to sensitive local data. For this reason, experts proposed solutions that combine federated learning with Differential Privacy strategies and community-driven approaches, which involve combining data from neighbor clients to make the individual local updates less dependent on local sensitive data. In this paper, we identify a crucial security flaw in such a configuration, and we design an attack capable of deceiving state-of-the-art defenses for federated learning. The proposed attack includes two operating modes, the first one focusing on convergence inhibition (Adversarial Mode), and the second one aiming at building a deceptive rating injection on the global federated model (Backdoor Mode). The experimental results show the effectiveness of our attack in both its modes, returning on average 60% performance detriment in all the tests on Adversarial Mode and fully effective backdoors in 93% of cases for the tests performed on Backdoor Mode.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
奋斗幻姬发布了新的文献求助10
刚刚
可爱的函函应助zychaos采纳,获得10
刚刚
1秒前
桐桐应助超123采纳,获得10
2秒前
青苹果qq完成签到 ,获得积分10
4秒前
tangtang发布了新的文献求助10
4秒前
爱吃苦瓜完成签到,获得积分10
4秒前
kke完成签到,获得积分10
5秒前
5秒前
淡淡溪灵完成签到 ,获得积分10
6秒前
6秒前
knight发布了新的文献求助10
7秒前
7秒前
7秒前
好人一生平安完成签到,获得积分10
8秒前
8秒前
9秒前
年轻绮波完成签到,获得积分10
9秒前
Jeffrey2026完成签到,获得积分10
10秒前
11秒前
香蕉觅云应助科研通管家采纳,获得10
11秒前
大个应助科研通管家采纳,获得10
11秒前
无花果应助科研通管家采纳,获得10
11秒前
JamesPei应助科研通管家采纳,获得10
11秒前
SciGPT应助科研通管家采纳,获得10
11秒前
CodeCraft应助科研通管家采纳,获得10
11秒前
hint应助科研通管家采纳,获得10
11秒前
tkx是流氓兔完成签到,获得积分10
11秒前
乐乐应助科研通管家采纳,获得10
11秒前
烟花应助科研通管家采纳,获得10
12秒前
12秒前
12秒前
小蘑菇应助科研通管家采纳,获得10
12秒前
NexusExplorer应助科研通管家采纳,获得10
12秒前
zychaos发布了新的文献求助10
12秒前
12秒前
XXXAAA应助科研通管家采纳,获得30
12秒前
大模型应助科研通管家采纳,获得10
12秒前
香蕉面包完成签到 ,获得积分10
12秒前
XXXAAA应助科研通管家采纳,获得50
12秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Les Mantodea de Guyane Insecta, Polyneoptera 2000
Emmy Noether's Wonderful Theorem 1200
Leading Academic-Practice Partnerships in Nursing and Healthcare: A Paradigm for Change 800
基于非线性光纤环形镜的全保偏锁模激光器研究-上海科技大学 800
Signals, Systems, and Signal Processing 610
Research Methods for Business: A Skill Building Approach, 9th Edition 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6410972
求助须知:如何正确求助?哪些是违规求助? 8230157
关于积分的说明 17465058
捐赠科研通 5463897
什么是DOI,文献DOI怎么找? 2887041
邀请新用户注册赠送积分活动 1863492
关于科研通互助平台的介绍 1702558