Feature Reconstruction Attacks and Countermeasures of DNN training in Vertical Federated Learning

10/13/2022
by   Peng Ye, et al.
0

Federated learning (FL) has increasingly been deployed, in its vertical form, among organizations to facilitate secure collaborative training over siloed data. In vertical FL (VFL), participants hold disjoint features of the same set of sample instances. Among them, only one has labels. This participant, known as the active party, initiates the training and interacts with the other participants, known as the passive parties. Despite the increasing adoption of VFL, it remains largely unknown if and how the active party can extract feature data from the passive party, especially when training deep neural network (DNN) models. This paper makes the first attempt to study the feature security problem of DNN training in VFL. We consider a DNN model partitioned between active and passive parties, where the latter only holds a subset of the input layer and exhibits some categorical features of binary values. Using a reduction from the Exact Cover problem, we prove that reconstructing those binary features is NP-hard. Through analysis, we demonstrate that, unless the feature dimension is exceedingly large, it remains feasible, both theoretically and practically, to launch a reconstruction attack with an efficient search-based algorithm that prevails over current feature protection techniques. To address this problem, we develop a novel feature protection scheme against the reconstruction attack that effectively misleads the search to some pre-specified random values. With an extensive set of experiments, we show that our protection scheme sustains the feature reconstruction attack in various VFL applications at no expense of accuracy loss.

READ FULL TEXT

page 1

page 11

research
06/19/2023

Practical and General Backdoor Attacks against Vertical Federated Learning

Federated learning (FL), which aims to facilitate data collaboration acr...
research
07/07/2023

Incentive Allocation in Vertical Federated Learning Based on Bankruptcy Problem

Vertical federated learning (VFL) is a promising approach for collaborat...
research
07/24/2022

Privacy Against Inference Attacks in Vertical Federated Learning

Vertical federated learning is considered, where an active party, having...
research
02/10/2023

Privacy Against Agnostic Inference Attacks in Vertical Federated Learning

A novel form of inference attack in vertical federated learning (VFL) is...
research
10/20/2020

Feature Inference Attack on Model Predictions in Vertical Federated Learning

Federated learning (FL) is an emerging paradigm for facilitating multipl...
research
04/18/2023

BadVFL: Backdoor Attacks in Vertical Federated Learning

Federated learning (FL) enables multiple parties to collaboratively trai...
research
02/17/2021

Label Leakage and Protection in Two-party Split Learning

In vertical federated learning, two-party split learning has become an i...

Please sign up or login with your details

Forgot password? Click here to reset