Privacy Analysis of Federated Learning via Dishonest Servers
Tre’ R. Jeter, My T. Thai · 2023
Federated Learning (FL) has gained popularity for its ability to improve model training while protecting user privacy. However, recent studies have shown that FL can be vulnerable to active reconstruction attacks by dishonest servers. Specifically, a dishonest server can obtain users’ private data in numerous ways via gradient inversion based on the core neural network concept of neuron activation. Addressing this style of attack is imperative to preserve user privacy and remains a major challenge due to its sophisticated nature. In this paper, we examine various active reconstruction attacks by a dishonest server and provide comprehensive evaluations to demonstrate their effectiveness and practicality, highlighting the risks associated with FL systems.