Researchers have developed FedCVESA, a novel method to conduct "Taking Away Training Data" (TATD) attacks within federated learning environments. This white-box attack targets specific clients to encode private training data into model parameters, referred to as carrier parameters. To counteract the overwriting that occurs during standard server aggregation in federated learning, FedCVESA employs segmented aggregation, preserving these critical carrier parameters while allowing normal averaging for the rest. Experiments on datasets like MNIST and CIFAR-10 demonstrated that FedCVESA can successfully extract meaningful private training images, even under non-IID data distributions, while maintaining acceptable utility for the main task. AI
IMPACT Highlights significant privacy risks in federated learning, potentially impacting the adoption and security of distributed AI systems.
RANK_REASON The cluster contains two identical arXiv papers detailing a new method for data privacy attacks in federated learning.
- CIFAR-10
- Correlation Value Encoding Attack
- Dirichlet
- Fashion-MNIST
- FedCVESA
- federated learning
- MNIST
- Pearson product-moment correlation coefficient
- Taking Away Training Data
AI-generated summary · Google Gemini · from 3 sources. How we write summaries →