AdvUSL: Targeted Adversarial Attack against U-shaped Split Learning
Yunxiao He, Chunqiang Hu, Yuwen Pu, Jiahao Chen, Xingwang Li · 2024
Split Learning is an emerging Distributed Machine Learning which allows clients and the server to collaborative train a model by splitting it successively. This approach not only addresses data scarcity, but also enhances data privacy while reducing communication and computation overhead. However, existing research on the security of Split Learning primarily focuses on privacy protection, neglecting model security. To fill this gap, we propose AdvUSL, a targeted adversarial attack method against U-shaped Split Learning. AdvUSL trains a surrogate model inexpensively with a small amount of labeled data; matches intermediate embedding and labels to infer clients' labels, and uses the matched embeddings as anchors to conduct targeted adversarial attacks. Comprehensive experiments demonstrate that AdvUSL outperforms traditional white-box adversarial attacks, validating the effectiveness of our method.