Evaluating Differential Privacy Against Membership Inference in Federated Learning: Insights from the NIST Genomics Red Team Challenge
AI 摘要
该论文评估了差分隐私防御联邦学习中成员推断攻击的有效性,并提出了一种堆叠攻击策略。
主要贡献
- 提出了一种新的堆叠攻击策略,提高了成员推断攻击的准确率。
- 评估了不同差分隐私级别下成员推断攻击的性能。
- 提供了联邦学习中差分隐私防御成员推断攻击的实证分析。
方法论
该论文提出一种基于七个黑盒估计器的堆叠攻击策略,通过元分类器训练,并利用NIST的基因组数据进行实验评估。
原文摘要
While Federated Learning (FL) mitigates direct data exposure, the resulting trained models remain susceptible to membership inference attacks (MIAs). This paper presents an empirical evaluation of Differential Privacy (DP) as a defense mechanism against MIAs in FL, leveraging the environment of the 2025 NIST Genomics Privacy-Preserving Federated Learning (PPFL) Red Teaming Event. To improve inference accuracy, we propose a stacking attack strategy that ensembles seven black-box estimators to train a meta-classifier on prediction probabilities and cross-entropy losses. We evaluate this methodology against target models under three privacy configurations: an unprotected convolutional neural network (CNN, $ε=\infty$), a low-privacy DP model ($ε=200$), and a high-privacy DP model ($ε=10$). The attack outperforms all baselines in the No DP and Low Privacy settings and, critically, maintains measurable membership leakage at $ε=200$ where a single-signal LiRA baseline collapses. Evaluated on an independent third-party benchmark, these results provide an empirical characterisation of how stacking-based inference degrades across calibrated DP tiers in FL.