paper-with-me

홈 › Papers

TimberStrike: Dataset Reconstruction Attack Revealing Privacy Leakage in Federated Tree-Based Systems

2025-06-09 · Marco Di Gennaro, Giovanni De Lucia, Stefano Longari, Stefano Zanero, Michele Carminati

Federated Learning has emerged as a privacy-oriented alternative to centralized Machine Learning, enabling collaborative model training without direct data sharing. While extensively studied for neural networks, the security and privacy implications of tree-based models remain underexplored. This work introduces TimberStrike, an optimization-based dataset reconstruction attack targeting horizontally federated tree-based models. Our attack, carried out by a single client, exploits the discrete nature of decision trees by using split values and decision paths to infer sensitive training data from other clients. We evaluate TimberStrike on State-of-the-Art federated gradient boosting implementations across multiple frameworks, including Flower, NVFlare, and FedTree, demonstrating their vulnerability to privacy breaches. On a publicly available stroke prediction dataset, TimberStrike consistently reconstructs between 73.05% and 95.63% of the target dataset across all implementations. We further analyze Differential Privacy, showing that while it partially mitigates the attack, it also significantly degrades model performance. Our findings highlight the need for privacy-preserving mechanisms specifically designed for tree-based Federated Learning systems, and we provide preliminary insights into their design.

📄 PDF Abstract BibTeX arXiv:2506.07605

Code (1)

necst/timberstrike 공식 구현

Tasks

Federated LearningPrivacy PreservingReconstruction Attack

Similar Papers 제목 키워드 기반

BEAS: Blockchain Enabled Asynchronous & Secure Federated Machine Learning

2022-02-06 · Arup Mondal, Harpreet Virk, Debayan Gupta

Federated Learning (FL) enables multiple parties to distributively train a ML model without revealing their private datasets. However, it assumes trust in the centralized aggregator which stores and aggregates model upda…

Anomaly DetectionBIG-bench Machine LearningData PoisoningFederated Learning+1

Gradient-Guided Conditional Diffusion Models for Private Image Reconstruction: Analyzing Adversarial Impacts of Differential Privacy and Denoising

2024-11-05 · Tao Huang, Jiayang Meng, Hong Chen, Guolong Zheng 외

We investigate the construction of gradient-guided conditional diffusion models for reconstructing private images, focusing on the adversarial interplay between differential privacy noise and the denoising capabilities o…

DenoisingImage GenerationImage Reconstruction

Analysis and Mitigations of Reverse Engineering Attacks on Local Feature Descriptors

2021-05-09 · Deeksha Dangwal, Vincent T. Lee, Hyo Jin Kim, Tianwei Shen 외

As autonomous driving and augmented reality evolve, a practical concern is data privacy. In particular, these applications rely on localization based on user images. The widely adopted technology uses local feature descr…

Autonomous Driving

Score-based Membership Inference on Diffusion Models

2025-09-29 · Mingxing Rao, Bowen Qu, Daniel Moyer arxiv

Membership inference attacks (MIAs) against Diffusion Models (DMs) raise pressing privacy concerns by revealing whether a sample was part of the training set. While existing methods typically rely on measuring reconstruc…

Safeguarding Graph Neural Networks against Topology Inference Attacks

2025-09-05 · Jie Fu, Yuan Hong, Zhili Chen, Wendy Hui Wang arxiv

Graph Neural Networks (GNNs) have emerged as powerful models for learning from graph-structured data. However, their widespread adoption has raised serious privacy concerns. While prior research has primarily focused on …