arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.02971cs.CRcs.LGcs.NI

联邦学习中的隐私泄露:面向车载边缘网络惯性感知的基于梯度的客户端身份推断与防御

Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks

  • King Fahd University of Petroleum and Minerals(法赫德国王石油与矿产大学)

机构由 AI 辅助整理,请以论文原文为准。

Ali Akarma, Toqeer Ali Syed, Muhammad Khan, Qurat-ul-ain Mastoi, Adeel Ahmad

AI总结:

该研究针对车载边缘网络联邦学习,发现服务器可通过梯度近乎完美推断客户端身份,提出轻量级防御与集成联邦学习方案,实现隐私-效用平衡并验证了方法有效性。

AI中文摘要:

随着车载网络向5G/6G边缘智能演进,联邦学习(FL)被广泛推广为一种隐私保护方式,供车辆与基础设施训练共享模型而不暴露原始传感器数据。然而,客户端传输的更新仍会泄露足够信息以识别发送者,这威胁到安全关键型车万物联网(V2X)应用所依赖的匿名性,同时加剧了对抗机器学习、模型投毒和后门攻击等现有问题。我们研究服务器端通过惯性(IMU)测量从传输的权重增量中进行客户端身份推断,以UCI人类活动识别(HAR)基准作为联网车辆车载IMU流的可访问代理进行评估。在5种攻击分类器和5种非独立同分布(non-IID)划分下,半诚实但好奇的服务器从未受防御的更新中以接近完美的准确率(约1.000)恢复客户端身份,证实了具体的可识别性风险。随后,我们通过在固定裁剪值(C=1.0)下扫描高斯噪声(σ取值为{0.00, 0.05, 0.10, 0.20, 0.50, 1.00}),量化了轻量级“裁剪后加噪”防御的隐私-效用权衡,并通过Renyi accounting报告了形式化(ε, δ)-差分隐私(DP)预算。一个实用区间(σ∈[0.1, 0.2])可将攻击准确率降至接近随机水平,同时使相对FL准确率损失低于5%。集成联邦学习(Ensemble FL)提供互补的结构性隐私,具有1/K匿名集界且无噪声开销。结果通过密码学(SHA-256)训练/评估梯度不相交性、3个随机种子和计数归一化的攻击者优势指标得到支撑。我们明确将HAR作为代理,并讨论对真实车载遥测数据进行验证所需的条件。

英文摘要:

As vehicular networks move toward 5G/6G edge intelligence, federated learning (FL) is widely promoted as a privacy-preserving way for vehicles and infrastructure to train shared models without exposing raw sensor data. Yet the updates clients transmit still leak enough information to identify who sent them, which threatens the anonymity that safety-critical V2X applications assume and adds to existing concerns over adversarial ML, model poisoning, and backdoor attacks. We study server-side client identity inference from transmitted weight deltas using inertial (IMU) measurements, evaluated on the UCI Human Activity Recognition (HAR) benchmark as an accessible proxy for the IMU streams produced onboard connected vehicles. Across five attack classifiers and five non-IID partitions, an honest-but-curious server recovers client identity with near-perfect accuracy (approximately 1.000) from undefended updates, confirming a concrete identifiability risk. We then quantify the privacy-utility trade-off of a lightweight clip-then-noise defense by sweeping Gaussian noise (sigma in {0.00, 0.05, 0.10, 0.20, 0.50, 1.00}) at fixed clipping (C=1.0), and report formal (epsilon, delta)-DP budgets through Renyi accounting. A practical region (sigma in [0.1, 0.2]) drives attack accuracy to near-random while costing under 5% relative FL accuracy. Ensemble FL supplies complementary structural privacy with a 1/K anonymity-set bound and no noise penalty. Results are supported by cryptographic (SHA-256) train/evaluation gradient disjointness, three seeds, and a count-normalized attacker-advantage metric. We position HAR explicitly as a proxy and discuss what validation on true vehicular telemetry would require.

补充信息

↑