paper-with-me

홈 › Papers

Secure Aggregation is Not Private Against Membership Inference Attacks

2024-03-26 · Khac-Hoang Ngo, Johan Östman, Giuseppe Durisi, Alexandre Graell i Amat

Secure aggregation (SecAgg) is a commonly-used privacy-enhancing mechanism in federated learning, affording the server access only to the aggregate of model updates while safeguarding the confidentiality of individual updates. Despite widespread claims regarding SecAgg's privacy-preserving capabilities, a formal analysis of its privacy is lacking, making such presumptions unjustified. In this paper, we delve into the privacy implications of SecAgg by treating it as a local differential privacy (LDP) mechanism for each local update. We design a simple attack wherein an adversarial server seeks to discern which update vector a client submitted, out of two possible ones, in a single training round of federated learning under SecAgg. By conducting privacy auditing, we assess the success probability of this attack and quantify the LDP guarantees provided by SecAgg. Our numerical results unveil that, contrary to prevailing claims, SecAgg offers weak privacy against membership inference attacks even in a single training round. Indeed, it is difficult to hide a local update by adding other independent local updates when the updates are of high dimension. Our findings underscore the imperative for additional privacy-enhancing mechanisms, such as noise injection, in federated learning.

📄 PDF Abstract BibTeX arXiv:2403.17775

Code (1)

khachoang1412/SecAgg_not_private 공식 구현

Tasks

Federated LearningPrivacy Preserving

Similar Papers 제목 키워드 기반

PRICURE: Privacy-Preserving Collaborative Inference in a Multi-Party Setting

2021-02-19 · Ismat Jarin, Birhanu Eshete

When multiple parties that deal with private data aim for a collaborative prediction task such as medical image classification, they are often constrained by data protection regulations and lack of trust among collaborat…

Collaborative Inferenceimage-classificationImage ClassificationInference Attack+4

Client-specific Property Inference against Secure Aggregation in Federated Learning

2023-03-07 · Raouf Kerkouche, Gergely Ács, Mario Fritz

Federated learning has become a widely used paradigm for collaboratively training a common model among different participants with the help of a central server that coordinates the training. Although only the model param…

Federated Learning

FuSeFL: Fully Secure and Scalable Federated Learning

2025-07-18 · Sahar Ghoflsaz Ghinani, Elaheh Sadredini arxiv

Federated Learning (FL) enables collaborative model training without centralizing client data, making it attractive for privacy-sensitive domains. While existing approaches employ cryptographic techniques such as homomor…

Federated Learning

Eluding Secure Aggregation in Federated Learning via Model Inconsistency

2021-11-14 · Dario Pasquini, Danilo Francati, Giuseppe Ateniese

Secure aggregation is a cryptographic protocol that securely computes the aggregation of its inputs. It is pivotal in keeping model updates private in federated learning. Indeed, the use of secure aggregation prevents th…

Federated Learning

Secure Embedding Aggregation for Federated Representation Learning

2022-06-18 · Jiaxiang Tang, Jinbao Zhu, Songze Li, Lichao Sun

We consider a federated representation learning framework, where with the assistance of a central server, a group of $N$ distributed clients train collaboratively over their private data, for the representations (or embe…

Federated LearningPrivacy PreservingRepresentation Learning