paper-with-me

홈 › Papers

Theoretically Unmasking Inference Attacks Against LDP-Protected Clients in Federated Vision Models

2025-06-16 · Quan Nguyen, Minh N. Vu, Truc Nguyen, My T. Thai

Federated Learning enables collaborative learning among clients via a coordinating server while avoiding direct data sharing, offering a perceived solution to preserve privacy. However, recent studies on Membership Inference Attacks (MIAs) have challenged this notion, showing high success rates against unprotected training data. While local differential privacy (LDP) is widely regarded as a gold standard for privacy protection in data analysis, most studies on MIAs either neglect LDP or fail to provide theoretical guarantees for attack success rates against LDP-protected data. To address this gap, we derive theoretical lower bounds for the success rates of low-polynomial time MIAs that exploit vulnerabilities in fully connected or self-attention layers. We establish that even when data are protected by LDP, privacy risks persist, depending on the privacy budget. Practical evaluations on federated vision models confirm considerable privacy risks, revealing that the noise required to mitigate these attacks significantly degrades models' utility.

📄 PDF Abstract BibTeX arXiv:2506.17292

Code (0)

등록된 구현이 없습니다.

Tasks

Federated Learning

Similar Papers 제목 키워드 기반

Unmasking Covert Intrusions: Detection of Fault-Masking Cyberattacks on Differential Protection Systems

2024-09-06 · Ahmad Mohammad Saber, Amr Youssef, Davor Svetinovic, Hatem Zeineldin 외

Line Current Differential Relays (LCDRs) are high-speed relays progressively used to protect critical transmission lines. However, LCDRs are vulnerable to cyberattacks. Fault-Masking Attacks (FMAs) are stealthy cyberatta…

The Devil's Advocate: Shattering the Illusion of Unexploitable Data using Diffusion Models

2023-03-15 · Hadi M. Dolatabadi, Sarah Erfani, Christopher Leckie

Protecting personal data against exploitation of machine learning models is crucial. Recently, availability attacks have shown great promise to provide an extra layer of protection against the unauthorized use of data to…

Denoising

Transfer Learning-Based Model Protection With Secret Key

2021-03-05 · MaungMaung AprilPyone, Hitoshi Kiya

We propose a novel method for protecting trained models with a secret key so that unauthorized users without the correct key cannot get the correct inference. By taking advantage of transfer learning, the proposed method…

Transfer Learning

Segmentations-Leak: Membership Inference Attacks and Defenses in Semantic Image Segmentation

2019-12-20 · ECCV 2020 8 · Yang He, Shadi Rahimian, Bernt Schiele, Mario Fritz

Today's success of state of the art methods for semantic segmentation is driven by large datasets. Data is considered an important asset that needs to be protected, as the collection and annotation of such datasets comes…

BIG-bench Machine LearningImage SegmentationSegmentationSemantic Segmentation

Training DNN Model with Secret Key for Model Protection

2020-08-06 · MaungMaung AprilPyone, Hitoshi Kiya

In this paper, we propose a model protection method by using block-wise pixel shuffling with a secret key as a preprocessing technique to input images for the first time. The protected model is built by training with suc…

model