Malicious server (MS) attacks have enabled the scaling of data stealing in federated learning to large batch sizes and secure aggregation, settings previously considered private. However, many concerns regarding client-side detectability of MS attacks were raised, questioning their practicality once they are publicly known. In this work, for the first time, we thoroughly study the problem of client-side detectability.We demonstrate that most prior MS attacks, which fundamentally rely on one of two key principles, are detectable by principled client-side checks. Further, we formulate desiderata for practical MS attacks and propose SEER, a novel attack framework that satisfies all desiderata, while stealing user data from gradients of realistic networks, even for large batch sizes (up to 512 in our experiments) and under secure aggregation. The key insight of SEER is the use of a secret decoder, which is jointly trained with the shared model. Our work represents a promising first step towards more principled treatment of MS attacks, paving the way for realistic data stealing that can compromise user privacy in real-world deployments.
翻译:恶意服务器攻击突破了联邦学习在批量大小和安全聚合场景下数据窃取的规模限制,这些场景此前被视为隐私安全的。然而,关于此类攻击被客户端检测可能性的担忧已引发广泛讨论,尤其质疑其一旦被公开后的实用性。本研究首次系统探讨了客户端侧的可检测性问题。我们证明,多数早期恶意服务器攻击本质上依赖两类核心原理,且均可被基于原则的客户端检测机制发现。进而,我们构建了实用化恶意服务器攻击的理想特征体系,并提出了SEER——一种满足所有理想特征的新型攻击框架。该框架能从实际网络的梯度中窃取用户数据,即使面对大批量大小(实验中达512)及安全聚合协议仍能生效。SEER的核心创新在于使用秘密解码器,该解码器与共享模型联合训练。本研究为恶意服务器攻击开启更富理论原则的处理方式迈出了关键第一步,为现实部署中可能危及用户隐私的数据窃取提供了可行性路径。