Multi-Party Computation (MPC) based Vertical federated learning (VFL) provides a promising solution for privacy-preserving machine learning. With this approach, fragmented dataset owners can collaborate to conduct neural network inference without disclosing their data and local model parameters. However, the current MPC-based VFL frameworks only provide semi-honest security, assuming all involved parties will consistently follow the protocol. We believe this assumption may not always hold true in reality. To enhance the security of MPC-based VFL protocols, it is essential to examine potential malicious behaviours within the semi-honest protocol execution that could lead to the leakage of model parameters. Drawing upon the model extraction attack of Muse, we demonstrate a novel model extraction attack specifically tailored for MPC-based VFL protocols with semi-honest security. To demonstrate the feasibility of our attack, we provide a detailed, step-by-step example illustrating how a malicious party in the MPC-based VFL can steal the entire model’s parameters. In experiments, we simulate the run time cost and total queries of our attack on multiple VFL structures, validating its applicability to real-world datasets.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Model Extraction Attack on MPC Hardened Vertical Federated Learning

  • Xinqian Wang,
  • Xiaoning Liu,
  • Xun Yi

摘要

Multi-Party Computation (MPC) based Vertical federated learning (VFL) provides a promising solution for privacy-preserving machine learning. With this approach, fragmented dataset owners can collaborate to conduct neural network inference without disclosing their data and local model parameters. However, the current MPC-based VFL frameworks only provide semi-honest security, assuming all involved parties will consistently follow the protocol. We believe this assumption may not always hold true in reality. To enhance the security of MPC-based VFL protocols, it is essential to examine potential malicious behaviours within the semi-honest protocol execution that could lead to the leakage of model parameters. Drawing upon the model extraction attack of Muse, we demonstrate a novel model extraction attack specifically tailored for MPC-based VFL protocols with semi-honest security. To demonstrate the feasibility of our attack, we provide a detailed, step-by-step example illustrating how a malicious party in the MPC-based VFL can steal the entire model’s parameters. In experiments, we simulate the run time cost and total queries of our attack on multiple VFL structures, validating its applicability to real-world datasets.