SRATTA : Sample Re-ATTribution Attack of Secure Aggregation in Federated Learning

06/13/2023
by   Tanguy Marchand, et al.
0

We consider a cross-silo federated learning (FL) setting where a machine learning model with a fully connected first layer is trained between different clients and a central server using FedAvg, and where the aggregation step can be performed with secure aggregation (SA). We present SRATTA an attack relying only on aggregated models which, under realistic assumptions, (i) recovers data samples from the different clients, and (ii) groups data samples coming from the same client together. While sample recovery has already been explored in an FL setting, the ability to group samples per client, despite the use of SA, is novel. This poses a significant unforeseen security threat to FL and effectively breaks SA. We show that SRATTA is both theoretically grounded and can be used in practice on realistic models and datasets. We also propose counter-measures, and claim that clients should play an active role to guarantee their privacy during training.

READ FULL TEXT

page 9

page 23

research
05/11/2022

Blockchain-based Secure Client Selection in Federated Learning

Despite the great potential of Federated Learning (FL) in large-scale di...
research
10/17/2020

Secure Weighted Aggregation in Federated Learning

Federated learning (FL) schemes enable multiple clients to jointly solve...
research
10/12/2022

Privacy of federated QR decomposition using additive secure multiparty computation

Federated learning (FL) is a privacy-aware data mining strategy keeping ...
research
05/12/2022

Secure Aggregation for Federated Learning in Flower

Federated Learning (FL) allows parties to learn a shared prediction mode...
research
09/19/2023

SPFL: A Self-purified Federated Learning Method Against Poisoning Attacks

While Federated learning (FL) is attractive for pulling privacy-preservi...
research
09/21/2023

Enabling Quartile-based Estimated-Mean Gradient Aggregation As Baseline for Federated Image Classifications

Federated Learning (FL) has revolutionized how we train deep neural netw...
research
10/27/2022

M3FGM:a node masking and multi-granularity message passing-based federated graph model for spatial-temporal data prediction

Researchers are solving the challenges of spatial-temporal prediction by...

Please sign up or login with your details

Forgot password? Click here to reset