Unleashing the Tiger: Inference Attacks on Split Learning

N/ACitations
Citations of this article
83Readers
Mendeley users who have this article in their library.
Get full text

Abstract

We investigate the security of split learning - -a novel collaborative machine learning framework that enables peak performance by requiring minimal resource consumption. In the present paper, we expose vulnerabilities of the protocol and demonstrate its inherent insecurity by introducing general attack strategies targeting the reconstruction of clients' private training sets. More prominently, we show that a malicious server can actively hijack the learning process of the distributed model and bring it into an insecure state that enables inference attacks on clients' data. We implement different adaptations of the attack and test them on various datasets as well as within realistic threat scenarios. We demonstrate that our attack can overcome recently proposed defensive techniques aimed at enhancing the security of the split learning protocol. Finally, we also illustrate the protocol's insecurity against malicious clients by extending previously devised attacks for Federated Learning.

Cite

CITATION STYLE

APA

Pasquini, D., Ateniese, G., & Bernaschi, M. (2021). Unleashing the Tiger: Inference Attacks on Split Learning. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 2113–2129). Association for Computing Machinery. https://doi.org/10.1145/3460120.3485259

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free