TY - JOUR
T1 - GRAMSSAT
T2 - An efficient label inference attack against two-party split learning based on gradient matching and semi-supervised learning
AU - Zhang, Lixin
AU - Gao, Xinyan
AU - Zhao, Bihe
AU - Guan, Zhenyu
AU - Bian, Song
N1 - Publisher Copyright:
© 2025 Elsevier Ltd
PY - 2025/9
Y1 - 2025/9
N2 - As a novel privacy-preserving paradigm for protecting the privacy of participant data and realizing the utility of data, split learning (SL) has gained wide attention and applications in various fields such as healthcare and media advertising. SL aims to collaboratively train a model using private input and labeled data from multiple parties, while exchanging only intermediate representations and corresponding backward gradients. We propose GRAMSSAT, a label inference attack that trains a surrogate model to replace the label owner's model. By leveraging a small amount of labeled auxiliary data, we treat the attack as a semi-supervised learning problem, designing a novel loss function that combines gradient matching, which enables the adversary to infer private labels during the SL process. Our experiments show that GRAMSSAT achieves label inference with improved efficiency and accuracy, enhancing attack performance by 9.14% to 42.77% compared to prior works e.g., Fu et al., USENIX Security 2022 across different datasets. In particular, in the case where the adversarial client's knowledge is limited (only known 1 or 2 labels per class), the inference accuracy of our proposed GRAMSSAT on the CIFAR-100 test set improves by 20.43% and 17.19% compared to the prior work. We also implement several defense mechanisms, including gradient compression and differential privacy. Our findings highlight the privacy risks in split learning and the need for more secure training techniques.
AB - As a novel privacy-preserving paradigm for protecting the privacy of participant data and realizing the utility of data, split learning (SL) has gained wide attention and applications in various fields such as healthcare and media advertising. SL aims to collaboratively train a model using private input and labeled data from multiple parties, while exchanging only intermediate representations and corresponding backward gradients. We propose GRAMSSAT, a label inference attack that trains a surrogate model to replace the label owner's model. By leveraging a small amount of labeled auxiliary data, we treat the attack as a semi-supervised learning problem, designing a novel loss function that combines gradient matching, which enables the adversary to infer private labels during the SL process. Our experiments show that GRAMSSAT achieves label inference with improved efficiency and accuracy, enhancing attack performance by 9.14% to 42.77% compared to prior works e.g., Fu et al., USENIX Security 2022 across different datasets. In particular, in the case where the adversarial client's knowledge is limited (only known 1 or 2 labels per class), the inference accuracy of our proposed GRAMSSAT on the CIFAR-100 test set improves by 20.43% and 17.19% compared to the prior work. We also implement several defense mechanisms, including gradient compression and differential privacy. Our findings highlight the privacy risks in split learning and the need for more secure training techniques.
KW - AI security
KW - Data privacy
KW - Label inference attack
KW - Split learning
KW - Surrogate model
UR - https://www.scopus.com/pages/publications/105010685993
U2 - 10.1016/j.jisa.2025.104159
DO - 10.1016/j.jisa.2025.104159
M3 - 文章
AN - SCOPUS:105010685993
SN - 2214-2134
VL - 93
JO - Journal of Information Security and Applications
JF - Journal of Information Security and Applications
M1 - 104159
ER -