Protecting Sensitive Property in Federated Learning via Adversarial Perturbation
Likun Zhang, Yahong Chen, Ben Niu, Jin Ping Cao, Fenghua Li · 2023
Federated Learning (FL) is a popular distributed learning paradigm that can effectively reduce privacy risks via sharing local model updates instead of the original training data. However, recent works have exploited sensitive properties of training data from the exchanged model updates. Existing defenses incur either unignorable computational overhead or significant accuracy drop to provide the expected a satisfying privacy guarantee. In this paper, we propose an adversarial learning-based defense against the property inference attack, termed FL-shield, which adds specially-crafted adversarial perturbation to local model updates. We first quantify layer-wise property leakage risk of a target model. For each layer with high privacy risk, a substitute attack model and a perturbation generator are trained simultaneously via adversarial learning. Thus, the clients can obtain perturbed local updates using the perturbation generator, such that their protected property values are obfuscated while the amount of noises added are maximally decreased. Empirical evaluations across a suite of datasets have demonstrated that FL-shield can effectively decrease the success rate of state-of-the-art property inference attacks to nearly a random guess and maintain the utility and convergence performance of the global model with both IID and non-IID partitioned training data, outperforming the existing defenses.