English

Active Membership Inference Attack under Local Differential Privacy in Federated Learning

Machine Learning 2023-08-30 v2 Artificial Intelligence Cryptography and Security

Abstract

Federated learning (FL) was originally regarded as a framework for collaborative learning among clients with data privacy protection through a coordinating server. In this paper, we propose a new active membership inference (AMI) attack carried out by a dishonest server in FL. In AMI attacks, the server crafts and embeds malicious parameters into global models to effectively infer whether a target data sample is included in a client's private training data or not. By exploiting the correlation among data features through a non-linear decision boundary, AMI attacks with a certified guarantee of success can achieve severely high success rates under rigorous local differential privacy (LDP) protection; thereby exposing clients' training data to significant privacy risk. Theoretical and experimental results on several benchmark datasets show that adding sufficient privacy-preserving noise to prevent our attack would significantly damage FL's model utility.

Keywords

Cite

@article{arxiv.2302.12685,
  title  = {Active Membership Inference Attack under Local Differential Privacy in Federated Learning},
  author = {Truc Nguyen and Phung Lai and Khang Tran and NhatHai Phan and My T. Thai},
  journal= {arXiv preprint arXiv:2302.12685},
  year   = {2023}
}

Comments

Published at AISTATS 2023

R2 v1 2026-06-28T08:48:52.603Z