TY - JOUR
T1 - LDIA
T2 - Label distribution inference attack against federated learning in edge computing
AU - Gu, Yuhao
AU - Bai, Yuebin
N1 - Publisher Copyright:
© 2023 Elsevier Ltd
PY - 2023/5
Y1 - 2023/5
N2 - With the popularity of IoT (Internet of Things) applications, edge computing has received lots of attention. To meet data privacy protection requirements of edge nodes and cope with their unbalanced data distribution, federated learning (FL), a distributed learning framework, is widely used in intelligent edge computing applications. However, recent studies have shown that FL still suffers from privacy leakage problems, including membership inference, data reconstruction, etc. However, these studies mainly focus on the feature information of private data. In this paper, we concern the user-level label privacy in FL. We propose LDIA, a label distribution inference attack against FL in edge computing, exploring the possibility that an honest but curious cloud server can infer the proportions of samples per label in the edge user's private data. LDIA is inspired by the observation that parameter changes in the output layer of a model can reflect the label distribution of training data. We use a neural network to learn individual features of the output layer updates over different label distributions, and then perform inference from local models uploaded by users. Our comprehensive evaluation shows that LDIA is effective on various datasets in different settings, demonstrating the severe privacy leakage in FL-based edge computing.
AB - With the popularity of IoT (Internet of Things) applications, edge computing has received lots of attention. To meet data privacy protection requirements of edge nodes and cope with their unbalanced data distribution, federated learning (FL), a distributed learning framework, is widely used in intelligent edge computing applications. However, recent studies have shown that FL still suffers from privacy leakage problems, including membership inference, data reconstruction, etc. However, these studies mainly focus on the feature information of private data. In this paper, we concern the user-level label privacy in FL. We propose LDIA, a label distribution inference attack against FL in edge computing, exploring the possibility that an honest but curious cloud server can infer the proportions of samples per label in the edge user's private data. LDIA is inspired by the observation that parameter changes in the output layer of a model can reflect the label distribution of training data. We use a neural network to learn individual features of the output layer updates over different label distributions, and then perform inference from local models uploaded by users. Our comprehensive evaluation shows that LDIA is effective on various datasets in different settings, demonstrating the severe privacy leakage in FL-based edge computing.
KW - Edge computing
KW - Federated learning
KW - Label distribution inference
KW - Privacy leakage
KW - User-level privacy
UR - https://www.scopus.com/pages/publications/85150777364
U2 - 10.1016/j.jisa.2023.103475
DO - 10.1016/j.jisa.2023.103475
M3 - 文章
AN - SCOPUS:85150777364
SN - 2214-2134
VL - 74
JO - Journal of Information Security and Applications
JF - Journal of Information Security and Applications
M1 - 103475
ER -