AIセキュリティポータル K Program
The Federation Strikes Back: A Survey of Federated Learning Privacy Attacks, Defenses, Applications, and Policy Landscape
Share
Abstract
Deep learning has shown incredible potential across a wide array of tasks, and accompanied by this growth has been an insatiable appetite for data. However, a large amount of data needed for enabling deep learning is stored on personal devices, and recent concerns on privacy have further highlighted challenges for accessing such data. As a result, federated learning (FL) has emerged as an important privacy-preserving technology that enables collaborative training of machine learning models without the need to send the raw, potentially sensitive, data to a central server. However, the fundamental premise that sending model updates to a server is privacy-preserving only holds if the updates cannot be "reverse engineered" to infer information about the private training data. It has been shown under a wide variety of settings that this privacy premise does not hold. In this survey paper, we provide a comprehensive literature review of the different privacy attacks and defense methods in FL. We identify the current limitations of these attacks and highlight the settings in which the privacy of an FL client can be broken. We further dissect some of the successful industry applications of FL and draw lessons for future successful adoption. We survey the emerging landscape of privacy regulation for FL and conclude with future directions for taking FL toward the cherished goal of generating accurate models while preserving the privacy of the data from its participants.
Hierarchical federated learning across heterogeneous cellular networks
Mehdi Salehi Heydar Abad, Emre Ozfatura, Deniz Gunduz, Ozgur Ercetin
Published: 2020
Deep learning with differential privacy
Martín Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, Li Zhang
Published: 2016
Secure single-server aggregation with (poly) logarithmic overhead
J. H. Bell, K. A. Bonawitz, A. Gascon, T. Lepoint, M. Raykova
Published: 2020
Reconstructing Individual Data Points in Federated Learning Hardened with Differential Privacy and Secure Aggregation
Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, Nicolas Papernot
Published: 1.10.2023
When the Curious Abandon Honesty: Federated Learning Is Not Private
Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, Nicolas Papernot
Published: 12.6.2021
Vulnerabilities in federated learning
Nader Bouacida, Prasant Mohapatra
Published: 2021
Federated learning with hierarchical clustering of local updates to improve training on non-IID data
Christopher Briggs, Zhong Fan, Peter Andras
Published: 2020
Membership inference attacks from first principles
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, Florian Tramer
Published: 2022
Federation in genomics pipelines: techniques and challenges
Somali Chaterji, Jinkyu Koo, Ninghui Li, Folker Meyer, Ananth Grama, Saurabh Bagchi
Published: 2019
Privacy and Fairness in Federated Learning: on the Perspective of Trade-off
Huiqiang Chen, Tianqing Zhu, Tao Zhang, Wanlei Zhou, Philip S Yu
Published: 2023
Xgboost: A scalable tree boosting system
T. Chen, C. Guestrin
Published: 2016
D-DAE: defense-penetrating model extraction attacks
Y. Chen, R. Guan, X. Gong, J. Dong, M. Xue
Published: 2023
Secureboost: A lossless federated learning framework
K. Cheng, T. Fan, Y. Jin, Y. Liu, T. Chen, D. Papadopoulos, Q. Yang
Published: 2021
Homomorphic encryption for arithmetic of approximate numbers
Jung Hee Cheon, Andrey Kim, Miran Kim, Yongsoo Song
Published: 2017
Heterogeneous Ensemble Knowledge Transfer for Training Large Models in Federated Learning
Yae Jee Cho, Andre Manoel, Gauri Joshi, Robert Sim, Dimitrios Dimitriadis
Published: 2022
Federated learning for predicting clinical outcomes in patients with COVID-19
I. Dayan, H. R. Roth, A. Zhong, A. Harouni, A. Gentili, A. Z. Abidin, A. Liu, A. B. Costa, B. J. Wood, C.-S. Tsai
Published: 2021
Unlocking High-Accuracy Differentially Private Image Classification through Scale
Soham De, Leonard Berrada, Jamie Hayes, Samuel L. Smith, Borja Balle
Published: 4.29.2022
Hetero{FL}: Computation and Communication Efficient Federated Learning for Heterogeneous Clients
Enmao Diao, Jie Ding, Vahid Tarokh
Published: 2021
Model inversion attack with least information and an in-depth analysis of its disparate vulnerability
Sayanton V Dibbo, Dae Lim Chung, Shagufta Mehnaz
Published: 2023
New directions in cryptography
Whitfield Diffie, Martin Hellman
Published: 1976
Differential privacy: A survey of results
C. Dwork
Published: 2008
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, Adam Smith
Published: 2006
Differential privacy for deep and federated learning: A survey
A. E. Ouadrhiri, A. M. Abdelhadi
Published: 2022
How Much Privacy Does Federated Learning with Secure Aggregation Guarantee?
Ahmed Roushdy Elkordy, Jiang Zhang, Yahya H. Ezzeldin, Konstantinos Psounis, Salman Avestimehr
Published: 8.4.2022
Privacy preserving machine learning with homomorphic encryption and federated learning
Haokun Fang, Quan Qian
Published: 2021
Min-max cost optimization for efficient hierarchical federated learning in wireless edge networks
Jie Feng, Lei Liu, Qingqi Pei, Keqin Li
Published: 2021
Convergence de la répartition empirique vers la répartition théorique
Robert Fortet, Edith Mourier
Published: 1953
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, Thomas Ristenpart
Published: 2015
Truly privacy-preserving federated analytics for precision medicine with multiparty homomorphic encryption
David Froelicher, Juan R Troncoso-Pastoriza, Jean Louis Raisaro, Michel A Cuendet, Joao Sa Sousa, Hyunghoon Cho, Bonnie Berger, Jacques Fellay, Jean-Pierre Hubaux
Published: 2021
Property inference attacks on fully connected neural networks using permutation invariant representations
K. Ganju, Q. Wang, W. Yang, C. A. Gunter, N. Borisov
Published: 2018
Model extraction attacks and defenses on cloud-based machine learning models
Xueluan Gong, Qian Wang, Yanjiao Chen, Wang Yang, Xinchang Jiang
Published: 2020
Do gradient inversion attacks make federated learning unsafe?
Ali Hatamizadeh, Hongxu Yin, Pavlo Molchanov, Andriy Myronenko, Wenqi Li, Prerna Dogra, Andrew Feng, Mona G Flores, Jan Kautz, Daguang Xu
Published: 2023
Gradvit: Gradient inversion of vision transformers
Ali Hatamizadeh, Hongxu Yin, Holger R Roth, Wenqi Li, Jan Kautz, Daguang Xu, Pavlo Molchanov
Published: 2022
Melloddy: Cross-pharma federated learning at unprecedented scale unlocks benefits in qsar without compromising proprietary information
Wouter Heyndrickx, Lewis Mervin, Tobias Morawietz, Noé Sturm, Lukas Friedrich, Adam Zalewski, Anastasia Pentina, Lina Humbeck, Martijn Oldenhof, Ritsuya Niwayama
Published: 2023
Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning
Briland Hitaj, Giuseppe Ateniese, Fernando Perez-Cruz
Published: 2.24.2017
Papaya: Practical, private, and scalable federated learning
Dzmitry Huba, John Nguyen, Kshitiz Malik, Ruiyu Zhu, Mike Rabbat, Ashkan Yousefpour, Carole-Jean Wu, Hongyuan Zhan, Pavel Ustinov, Harish Srinivas
Published: 2022
Practical blind membership inference attack via differential comparisons
Bo Hui, Yuchen Yang, Haolin Yuan, Philippe Burlina, Neil Zhenqiang Gong, Yinzhi Cao
Published: 2021
Revisiting Membership Inference Under Realistic Assumptions
Bargav Jayaraman, Lingxiao Wang, Katherine Knipmeyer, Quanquan Gu, David Evans
Published: 2021
FastSecAgg: Scalable Secure Aggregation for Privacy-Preserving Federated Learning
Swanand Kadhe, Nived Rajaraman, O. Ozan Koyluoglu, Kannan Ramchandran
Published: 9.24.2020
Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning using Independent Component Analysis
Sanjay Kariyappa, Chuan Guo, Kiwan Maeng, Wenjie Xiong, G. Edward Suh, Moinuddin K Qureshi, Hsien-Hsin S. Lee
Published: 9.13.2022
Federated learning as a privacy solution-an overview
Mashal Khan, Frank G Glavin, Matthias Nickles
Published: 2023
Federated learning with local differential privacy: Trade-offs between privacy, utility, and communication
M. Kim, O. Günlüyü, R. F. Schaefer
Published: 2021
A unified theory of decentralized sgd with changing topology and local updates
Anastasia Koloskova, Nicolas Loizou, Sadra Boreiri, Martin Jaggi, Sebastian Stich
Published: 2020
A tale of two synchronizing clocks
Jinkyu Koo, Rajesh K Panta, Saurabh Bagchi, Luis Montestruque
Published: 2009
Gradient disaggregation: Breaking privacy in federated learning by reconstructing the user participant matrix
Maximilian Lam, Gu-Yeon Wei, David Brooks, Vijay Janapa Reddi, Michael Mitzenmacher
Published: 2021
Enhancing the transferability of adversarial attacks through variance tuning
Xiaosen Wang, Kun He
Published: 2021
Share