Enhancing Membership Inference Attacks in Federated Learning Based on Overfitting Property
At a glance
- Citations
- 1
- References
- 10
- Comments
- 0
Abstract
Membership inference attacks have been proposed to infer whether a specific sample is in the training dataset of a victim model. Inferred membership may reveal sensitive information, e.g., personal health condition deduced from a disease prediction model. In federated learning where local datasets of different participants are supposed to be protected, membership inference attacks may still pose a privacy threat. However, existing membership inference attacks in federated learning select the final epoch and random intermediate epochs during training to solicit features for the attack, which may lead to poor attack performance. In this paper, we propose a novel membership inference attack in federated learning, which attempt to find the key epoch during training that is most indicative of the differences between member and non-member samples. Inspired by the overfitting phenomena that often occurs during the training of learning models, we derive the key epoch as the onset of overfitting. We design efficient algorithms to pinpoint the key epoch and leverage attention mechanism to weight the importance of different features. We evaluate our scheme on four datasets and compare experimental results with state-of-the-art attack algorithms. Experimental results demonstrate that our attack outperforms existing works in terms of inference accuracy.
Publication details
- DOI
- 10.1109/msn63567.2024.00135
- OpenAlex
- W4411584658
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.