Malicious server (MS) attacks have enabled the scaling of data stealing in federated learning to large batch sizes and secure aggregation, settings previously considered private. However, many concerns regarding client-side detectability of MS attacks were raised, questioning their practicality once they are publicly known. In this work, for the first time, we thoroughly study the problem of client-side detectability.We demonstrate that most prior MS attacks, which fundamentally rely on one of two key principles, are detectable by principled client-side checks. Further, we formulate desiderata for practical MS attacks and propose SEER, a novel attack framework that satisfies all desiderata, while stealing user data from gradients of realistic networks, even for large batch sizes (up to 512 in our experiments) and under secure aggregation. The key insight of SEER is the use of a secret decoder, which is jointly trained with the shared model. Our work represents a promising first step towards more principled treatment of MS attacks, paving the way for realistic data stealing that can compromise user privacy in real-world deployments.
翻译:恶意服务器攻击已使联邦学习中的数据窃取扩展到大批次数据和安全聚合场景,而此前这些设置被认为具有隐私保护性。然而,关于客户端对恶意服务器攻击可检测性的担忧已被广泛提出,质疑其在公开后是否仍具实用性。本工作首次系统研究了客户端侧的可检测性问题。我们证明,先前绝大多数依赖两类核心原理的恶意服务器攻击,均可通过原则性的客户端检测机制识别。进一步,我们制定了实用化恶意服务器攻击的期望特性,并提出SEER——一种满足所有期望特性的新型攻击框架,即使面对真实网络梯度、大批次数据(实验中最高达512)及安全聚合场景,仍能窃取用户数据。SEER的核心创新在于使用与共享模型联合训练的秘密切换器。本工作为更严谨地处理恶意服务器攻击迈出了具有前景的第一步,为在真实部署中威胁用户隐私的现实数据窃取方法铺平道路。