conference-paper

Enhancing Membership Inference Attacks in Federated Learning Based on Overfitting Property

Research footprint

At a glance

Citations
1
References
10
Comments
0
Paper overview

Abstract

Membership inference attacks have been proposed to infer whether a specific sample is in the training dataset of a victim model. Inferred membership may reveal sensitive information, e.g., personal health condition deduced from a disease prediction model. In federated learning where local datasets of different participants are supposed to be protected, membership inference attacks may still pose a privacy threat. However, existing membership inference attacks in federated learning select the final epoch and random intermediate epochs during training to solicit features for the attack, which may lead to poor attack performance. In this paper, we propose a novel membership inference attack in federated learning, which attempt to find the key epoch during training that is most indicative of the differences between member and non-member samples. Inspired by the overfitting phenomena that often occurs during the training of learning models, we derive the key epoch as the onset of overfitting. We design efficient algorithms to pinpoint the key epoch and leverage attention mechanism to weight the importance of different features. We evaluate our scheme on four datasets and compare experimental results with state-of-the-art attack algorithms. Experimental results demonstrate that our attack outperforms existing works in terms of inference accuracy.

Record transparency

Publication details

DOI
10.1109/msn63567.2024.00135
OpenAlex
W4411584658
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.