BI-GAN: Batch Inversion Membership Inference Attack on Federated Learning
- Publisher:
- ACM
- Publication Type:
- Conference Proceeding
- Citation:
- Proceedings of the 17th ACM Workshop on Mobility in the Evolving Internet Architecture, MobiArch 2022, 2022, pp. 31-36
- Issue Date:
- 2022-10-21
Open Access
Copyright Clearance Process
- Recently Added
- In Progress
- Open Access
This item is open access.
Federated Learning is a growing advanced collaborative machine learning framework that aims to preserve user-privacy data. However, multiple researchers have investigated attack methods from the server side via gradient inversion techniques or Generative Adversarial Networks (GAN) to reconstruct the raw data distributions from users. In this paper, we propose Batch Inversion GAN (BI-GAN), a novel membership inference attack that can recover user-level batch images from local updates, utilizing both gradient inversion techniques and GAN. Our attack is more stealthy since it only requires access to gradients and does not interfere with the global model performance and is more robust in terms of image batch recovery and victim classification. The experiments show that our attack recovers higher quality images of the victim with higher accuracy compared to other attacks.
Please use this identifier to cite or link to this item: