Vertical federated learning (VFL) allows an active party with a top model, and multiple passive parties with bottom models to collaborate. In this scenario, passive parties possessing only features may attempt to infer active party's private labels, making label inference attacks (LIAs) a significant threat. Previous LIA studies have claimed that well-trained bottom models can effectively represent labels. However, we demonstrate that this view is misleading and exposes the vulnerability of existing LIAs. By leveraging mutual information, we present the first observation of the "model compensation" phenomenon in VFL. We theoretically prove that, in VFL, the mutual information between layer outputs and labels increases with layer depth, indicating that bottom models primarily extract feature information while the top model handles label mapping. Building on this insight, we introduce task reassignment to show that the success of existing LIAs actually stems from the distribution alignment between features and labels. When this alignment is disrupted, the performance of LIAs declines sharply or even fails entirely. Furthermore, the implications of this insight for defenses are also investigated. We propose a zero-overhead defense technique based on layer adjustment. Extensive experiments across five datasets and five representative model architectures indicate that shifting cut layers forward to increase the proportion of top model layers in the entire model not only improves resistance to LIAs but also enhances other defenses.
翻译:纵向联邦学习(VFL)允许拥有顶部模型的主动方与多个拥有底部模型的被动方进行协作。在此场景中,仅拥有特征的被动方可能试图推断主动方的私有标签,这使得标签推理攻击(LIA)成为一项重大威胁。以往LIA研究声称,训练良好的底部模型能有效表征标签。然而,我们证明该观点具有误导性,并揭示了现有LIA的脆弱性。通过利用互信息,我们首次观察到VFL中的“模型补偿”现象。我们从理论上证明,在VFL中,层输出与标签之间的互信息随层深度增加而增强,这表明底部模型主要提取特征信息,而顶部模型负责标签映射。基于这一见解,我们引入任务重新分配,证明现有LIA的成功实则源于特征与标签之间的分布对齐。当这种对齐被破坏时,LIA的性能急剧下降甚至完全失效。此外,我们还探讨了这一见解对防御策略的启示。我们提出了一种基于层调整的零开销防御技术。在五个数据集和五种代表性模型架构上的大量实验表明,将切分层前移以增加顶部模型层在整个模型中的比例,不仅能提升对LIA的抵抗能力,还能增强其他防御措施的效果。