A generative adversarial network‐based client‐level handwriting forgery attack in federated learning scenario

Author:

Shi Lei12ORCID,Wu Han12,Ding Xu12,Xu Hao12,Pan Sinan12

Affiliation:

1. School of Computer Science and Information Engineering Hefei University of Technology Hefei Anhui China

2. Engineering Research Center of Safety Critical Industrial Measurement and Control Technology Ministry of Education Hefei Anhui China

Abstract

AbstractFederated learning (FL), celebrated for its privacy‐preserving features, has been revealed by recent studies to harbour security vulnerabilities that jeopardize client privacy, particularly through data reconstruction attacks that enable adversaries to recover original client data. This study introduces a client‐level handwriting forgery attack method for FL based on generative adversarial networks (GANs), which reveals security vulnerabilities existing in FL systems. It should be stressed that this research is purely for academic purposes, aiming to raise concerns about privacy protection and data security, and does not encourage illegal activities. Our novel methodology assumes an adversarial scenario wherein adversaries intercept a fraction of parameter updates via victim clients’ wireless communication channels, then use this information to train GAN for data recovery. Finally, the purpose of handwriting imitation is achieved. To rigorously assess and validate our methodology, experiments were conducted using a bespoke Chinese digit dataset, facilitating in‐depth analysis and robust verification of results. Our experimental findings demonstrated enhanced data recovery effectiveness, a client‐level attack and greater versatility compared to prior art. Notably, our method maintained high attack performance even with a streamlined GAN design, yielding increased precision and significantly faster execution times compared to standard methods. Specifically, our experimental numerical results revealed a substantial boost in reconstruction accuracy by 16.7%, coupled with a 51.9% decrease in computational time compared to the latest similar techniques. Furthermore, tests on a simplified version of our GAN exhibited an average 10% enhancement in accuracy, alongside a remarkable 70% reduction in time consumption. By surmounting the limitations of previous work, this study fills crucial gaps and affirms the effectiveness of our approach in achieving high‐accuracy client‐level data reconstruction within the FL context, thereby stimulating further exploration into FL security measures.

Funder

Natural Science Foundation of Anhui Province

Publisher

Wiley

Reference39 articles.

1. Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications

2. Generative Adversarial Networks

3. Chen C. &Campbell N. D.(2021).Understanding training‐data leakage from gradients in neural networks for image classification. arXiv preprint arXiv:2111.10178.

4. Flight track pattern recognition based on few labeled data with outliers;Fan Y.;Journal of Electronic Imaging,2021

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3