Defending Against Inference and Backdoor Attacks in Vertical Federated Learning via Mutual Information Regularization

Tianyuan Zou, Yang Liu, Xiaozhou Ye, Ye Ouyang, Ya-Qin Zhang · 2024

Vertical Federated Learning (VFL) is widely utilized in real-world applications to enable collaborative learning while protecting local data and models. However, previous works show that parties without labels (passive parties) in VFL can infer the sensitive label or feature information owned by the party with labels (active party), or execute backdoor attacks. Meanwhile, active party can also infer sensitive feature or attribute information from passive party. All these pose great challenges to VFL systems. Former defense methods tend to experience either a loss in overall effectiveness or are too specialized for specific tasks. In this work, we propose a novel method and a unified framework for defending various attacks in VFL altogether, namely Mutual Information Regularization Defense (MID), which limits the mutual information between private raw data and intermediate outputs to achieve a consistently better trade-off between model utility and privacy. We provide both theoretical and experimental evidence to confirm the effectiveness of our MID framework in defending against a wide range of label and feature inference attacks, along with backdoor attacks in VFL. These showcase its promising potential as a versatile and effective defense mechanism, not tied to any specific task.

Read the paper · More papers on PaperTik