Knowledge Graph Embedding (KGE) is a fundamental technique that extracts expressive representation from knowledge graph (KG) to facilitate diverse downstream tasks. The emerging federated KGE (FKGE) collaboratively trains from distributed KGs held among clients while avoiding exchanging clients' sensitive raw KGs, which can still suffer from privacy threats as evidenced in other federated model trainings (e.g., neural networks). However, quantifying and defending against such privacy threats remain unexplored for FKGE which possesses unique properties not shared by previously studied models. In this paper, we conduct the first holistic study of the privacy threat on FKGE from both attack and defense perspectives. For the attack, we quantify the privacy threat by proposing three new inference attacks, which reveal substantial privacy risk by successfully inferring the existence of the KG triple from victim clients. For the defense, we propose DP-Flames, a novel differentially private FKGE with private selection, which offers a better privacy-utility tradeoff by exploiting the entity-binding sparse gradient property of FKGE and comes with a tight privacy accountant by incorporating the state-of-the-art private selection technique. We further propose an adaptive privacy budget allocation policy to dynamically adjust defense magnitude across the training procedure. Comprehensive evaluations demonstrate that the proposed defense can successfully mitigate the privacy threat by effectively reducing the success rate of inference attacks from $83.1\%$ to $59.4\%$ on average with only a modest utility decrease.


翻译:知识图谱嵌入(KGE)是一项基础技术,它从知识图谱中提取具有表达能力的表征,以支持多样的下游任务。新兴的联邦知识图谱嵌入(FKGE)通过协作训练分布在客户端之间的知识图谱,同时避免交换客户端敏感的原始知识图谱数据,但这仍可能面临其他联邦模型训练(例如神经网络)中已证实的隐私威胁。然而,对于具有独特属性(不同于先前研究的模型)的FKGE而言,量化并防御此类隐私威胁仍属未探索领域。本文首次从攻击与防御双重视角对FKGE中的隐私威胁进行系统性研究。在攻击方面,我们通过提出三种新的推理攻击来量化隐私威胁,这些攻击通过成功推断受害者客户端中知识图谱三元组的存在性,揭示了显著的隐私风险。在防御方面,我们提出DP-Flames——一种具有私有选择机制的新型差分隐私FKGE方法,该方法利用FKGE的实体绑定稀疏梯度特性实现了更优的隐私-效用权衡,并结合了最先进的私有选择技术,提供了紧密的隐私核算。此外,我们还提出一种自适应隐私预算分配策略,以在训练过程中动态调整防御强度。综合评估表明,所提出的防御方法能够成功缓解隐私威胁,在仅轻微降低效用的条件下,将推理攻击的平均成功率从83.1%有效降低至59.4%。

0
下载
关闭预览

相关内容

知识图谱表示学习的对抗鲁棒性
专知会员服务
40+阅读 · 2022年10月7日
专知会员服务
22+阅读 · 2021年8月20日
最新《联邦学习Federated Learning》报告,Federated Learning
专知会员服务
92+阅读 · 2020年12月2日
专知会员服务
47+阅读 · 2020年10月31日
论文浅尝 | Temporal Knowledge Graph Completion Using Box Embeddings
开放知识图谱
1+阅读 · 2022年11月4日
知识图谱表示学习的对抗鲁棒性
专知
3+阅读 · 2022年10月7日
征稿 | International Joint Conference on Knowledge Graphs (IJCKG)
开放知识图谱
2+阅读 · 2022年5月20日
ICLR2019 图上的对抗攻击
图与推荐
17+阅读 · 2020年3月15日
Hierarchically Structured Meta-learning
CreateAMind
27+阅读 · 2019年5月22日
Transferring Knowledge across Learning Processes
CreateAMind
29+阅读 · 2019年5月18日
论文浅尝 | Global Relation Embedding for Relation Extraction
开放知识图谱
12+阅读 · 2019年3月3日
Unsupervised Learning via Meta-Learning
CreateAMind
44+阅读 · 2019年1月3日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2011年12月31日
Arxiv
0+阅读 · 2023年5月19日
VIP会员
最新内容
非对称防御中的自组织临界性:俄乌战争
专知会员服务
7+阅读 · 8月10日
《战争中的大语言模型监管》
专知会员服务
6+阅读 · 8月10日
《边缘计算关键技术分析及美军作战实践应用》
边缘计算的军事应用
专知会员服务
11+阅读 · 8月9日
一种考虑资源机动性的武器目标分配混合算法
专知会员服务
12+阅读 · 8月8日
相关基金
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2012年12月31日
国家自然科学基金
0+阅读 · 2011年12月31日
Top
微信扫码咨询专知VIP会员