A Stealthy Inference Attack on Split Learning with a Split-Fuse Defensive Measure

Sean Dougherty, Abhinav Kumar, Jie Hou, Reza Tourani, Atena M. Tabakhi · 2023

The privacy vulnerabilities and communication inefficiencies of federated learning have motivated the development of the split learning architecture. Google’s recent Federated Reconstruction architecture combines federated and split learning architectures into a unified design, aiming to improve communication and computation scalability. While split learning aims to protect the privacy of clients’ data, recent work has revealed its vulnerability to malicious adversaries through model poisoning. We aim to investigate the privacy aspect of split learning, as an independent architecture or the significant component of federated reconstruction architecture and expose its shortcomings. Different from the existing literature, we illustrate that an honest-but-curious adversary can infer the private properties of clients’ data without model poisoning or manipulation. We demonstrate the practicality of the property inference attack against split learning using various datasets. To reduce information leakages and protect clients’ privacy, we propose Bundle-Net architecture as a privacy-preserving distributed learning mechanism and assess its effectiveness in thwarting inference attacks.

Read the paper · More papers on PaperTik