What is it about?
Many academic works on data stealing attacks against federated learning assume that an adversarial client does not know what the training data look like. As clients in federated learning are required to train the model on their own data, this assumption is very unrealistic, often limiting attack performance and downplaying the associated risks. In this work we show how attackers can utilise the knowledge of what their own data looks like to steal private training data of other participants more effectively. Our findings show that collaborative medical image analysis settings can be particularly vulnerable to these attacks, leaking private patient data.
Featured Image
Photo by CDC on Unsplash
Why is it important?
Looking at data reconstruction (or stealing) attacks in a more realistic settings allows the policymakers and researchers from other fields to more critically assess the current state of distributed machine learning. This, in turn, encourages the community to realistically assess their threats and adjust the learning settings appropriately. Particularly, collaborative medical image analysis, which relies on the use of highly sensitive data, is shown to be much more vulnerable to attackers who participate in training and can relatively trivially steal sensitive patient data.
Perspectives
In general, privacy and security is a never-ending cat-and-mouse game between the attacker and the defender, where the former tries to exploit a system under the strictest threat model, whereas the latter tries to create a mechanism which is able to withstand the strongest, most well-informed attacker. However, in reality, the attacker typically has much more additional data to guide the exploitation process than the academic world cares to admit. This can result in catastrophic breaches of privacy, should these findings not be put into an appropriate realistic context. I sincerely hope that our in-depth analysis of a significantly more realistic training setting can help the researchers and the policymakers interested in the field of distributed learning to properly secure their learning settings with these practical results in mind, reducing the risks of privacy violations.
Dmitrii Usynin
Technische Universitat Munchen
Read the Original
This page is a summary of: Beyond Gradients: Exploiting Adversarial Priors in Model Inversion Attacks, ACM Transactions on Privacy and Security, April 2023, ACM (Association for Computing Machinery),
DOI: 10.1145/3592800.
You can read the full text:
Contributors
The following have contributed to this page







