Personal Attribute Leakage in Federated Speech Models
Federated learning is a common method for privacy-preserving training of machine learning models. In this paper, we analyze the vulnerability of ASR models to attribute inference attacks in the federated setting. We test a non-parametric white-box attack method under a passive threat model on three ASR models: Wav2Vec2, HuBERT, and Whisper. The attack operates solely on weight differentials without access to raw speech from target speakers. We demonstrate attack feasibility on sensitive demographic and clinical attributes: gender, age, accent, emotion, and dysarthria. Our findings indicate that attributes that are underrepresented or absent in the pre-training data are more vulnerable to such inference attacks. In particular, information about accents can be reliably inferred from all models. Our findings expose previously undocumented vulnerabilities in federated ASR models and offer insights towards improved security.
Code (0)
등록된 구현이 없습니다.
Tasks
Federated LearningSimilar Papers 제목 키워드 기반
User Consented Federated Recommender System Against Personalized Attribute Inference Attack
Recommender systems can be privacy-sensitive. To protect users' private historical interactions, federated learning has been proposed in distributed learning for user representations. Using federated recommender (FedRec)…
AttributeFederated LearningInference AttackRecommendation SystemsAttribute Inference Attack of Speech Emotion Recognition in Federated Learning Settings
Speech emotion recognition (SER) processes speech signals to detect and characterize expressed perceived emotions. Many SER application systems often acquire and transmit speech data collected at the client-side to remot…
AttributeEmotion RecognitionFederated LearningInference Attack+1An Attribute-Aligned Strategy for Learning Speech Representation
Advancement in speech technology has brought convenience to our life. However, the concern is on the rise as speech signal contains multiple personal attributes, which would lead to either sensitive information leakage o…
AttributeEmotion RecognitionPrivacy PreservingSpeaker Verification+1FastPFRec: A Fast Personalized Federated Recommendation with Secure Sharing
Graph neural network (GNN)-based federated recommendation systems effectively capture user-item relationships while preserving data privacy. However, existing methods often face slow convergence on graph data and privacy…
Recommendation SystemsGraph Neural NetworkPrivacy-Preserving Load Forecasting via Personalized Model Obfuscation
The widespread adoption of smart meters provides access to detailed and localized load consumption data, suitable for training building-level load forecasting models. To mitigate privacy concerns stemming from model-indu…
Federated LearningLoad ForecastingmodelPrivacy Preserving