跳到主要导航 跳到搜索 跳到主要内容

GRAMSSAT: An efficient label inference attack against two-party split learning based on gradient matching and semi-supervised learning

  • Lixin Zhang
  • , Xinyan Gao
  • , Bihe Zhao
  • , Zhenyu Guan
  • , Song Bian*
  • *此作品的通讯作者
  • Beihang University

科研成果: 期刊稿件文章同行评审

摘要

As a novel privacy-preserving paradigm for protecting the privacy of participant data and realizing the utility of data, split learning (SL) has gained wide attention and applications in various fields such as healthcare and media advertising. SL aims to collaboratively train a model using private input and labeled data from multiple parties, while exchanging only intermediate representations and corresponding backward gradients. We propose GRAMSSAT, a label inference attack that trains a surrogate model to replace the label owner's model. By leveraging a small amount of labeled auxiliary data, we treat the attack as a semi-supervised learning problem, designing a novel loss function that combines gradient matching, which enables the adversary to infer private labels during the SL process. Our experiments show that GRAMSSAT achieves label inference with improved efficiency and accuracy, enhancing attack performance by 9.14% to 42.77% compared to prior works e.g., Fu et al., USENIX Security 2022 across different datasets. In particular, in the case where the adversarial client's knowledge is limited (only known 1 or 2 labels per class), the inference accuracy of our proposed GRAMSSAT on the CIFAR-100 test set improves by 20.43% and 17.19% compared to the prior work. We also implement several defense mechanisms, including gradient compression and differential privacy. Our findings highlight the privacy risks in split learning and the need for more secure training techniques.

源语言英语
文章编号104159
期刊Journal of Information Security and Applications
93
DOI
出版状态已出版 - 9月 2025

学术指纹

探究 'GRAMSSAT: An efficient label inference attack against two-party split learning based on gradient matching and semi-supervised learning' 的科研主题。它们共同构成独一无二的学术指纹。

引用此