跳到主要导航 跳到搜索 跳到主要内容

Poisoning-Assisted Membership Inference in Federated Learning

  • Xukun Luan
  • , Yuanguo Bi
  • , Kuan Zhang
  • , Zixuan Huang
  • , Zhou Su
  • , Tom H. Luan
  • , Bing Hu
  • Northeastern University China
  • University of Nebraska-Lincoln
  • Xi'an Jiaotong University
  • Dalhousie University

科研成果: 期刊稿件文章同行评审

摘要

Federated learning (FL) is a distributed machine learning approach that allows multiple clients to collaboratively train a global model without sharing their local raw data. Despite this advantage, FL remains vulnerable to membership inference attacks (MIAs), which can compromise the membership privacy of federated clients. Nevertheless, existing MIAs exhibit significant performance degradation when the malicious clients lack knowledge of the target model and the training data of benign clients. In this paper, we propose a novel scheme, Temporal Evolution of the Poisoning Effects (TEPE), to conduct MIAs against black-box FL models without any prior knowledge of the target models or benign clients' training data. Specifically, we design a two-stage inference method: the poisoning process and the scoring process. For the poisoning process, we propose three poisoning strategies for three different auditing requirements. For the scoring process, we design a novel quantification method and an unsupervised inference model to extract membership features within the effects of poisoning attacks. The proposed attack leverages the intuition that if a sample is used by FL benign clients, its prediction may not be readily altered by poisoning attacks. Finally, we propose a modified random response algorithm (RR-Group) to detect our attacks, which can guarantee the performance of FL models and effectively reduce the attack performance of TEPE. Extensive experiments demonstrate that TEPE achieves competitive inference accuracy and F1-score compared to the most MIAs, while evading two representative defenses, except for our proposed detection method RR-Group.

源语言英语
期刊IEEE Transactions on Dependable and Secure Computing
DOI
出版状态已接受/待刊 - 2026
已对外发布

学术指纹

探究 'Poisoning-Assisted Membership Inference in Federated Learning' 的科研主题。它们共同构成独一无二的指纹。

引用此