arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.08476cs.CRcs.LG

当拓扑结构背叛隐私:去中心化联邦学习中针对安全聚合的基于格的重构攻击

When Topology Betrays Privacy: Lattice-Based Reconstruction Attacks on Secure Aggregation in Decentralized Federated Learning

Wenrui Yu, Changlong Ji, Johannes Bjerva, Qiongxiu Li

首次发表
浏览论文内容

中文总结 AI 辅助

本研究揭示去中心化联邦学习中稀疏拓扑下安全聚合的结构性泄露,通过建立与隐藏子集和问题的联系,设计基于格的重构攻击,成功恢复诚实节点的私有更新与训练数据。

中文摘要 AI 辅助

安全聚合(Secure Aggregation, SA)被广泛视为联邦学习(Federated Learning, FL)中针对模型更新泄露的强有力防御手段,因为它仅揭示聚合结果,同时隐藏个体更新。在去中心化联邦学习(Decentralized Federated Learning, DFL)中,SA通常以局部邻域聚合的形式实例化,其中每个节点获得其邻居的加权聚合结果。我们表明,这种局部性创造了一个结构性的泄露面:稀疏的去中心化拓扑结构为合谋的半诚实节点提供了不对称的聚合视图,暴露了诚实参与者私有状态的多个隐藏线性组合。从这些聚合视图重构私有状态从根本上具有挑战性,因为私有状态和聚合系数都是隐藏的。我们通过建立与隐藏子集和问题(Hidden Subset Sum Problem)——一个在密码学中研究已久的问题——的形式化联系来应对这一挑战。基于这一公式,我们设计了一种基于格的重构方法,该方法将格约简与结构过滤相结合,以重构受保护的模型状态。我们在稀疏DFL拓扑下对图像、表格和文本任务评估了我们的攻击。我们的结果表明,合谋的半诚实节点能够恢复诚实节点的原始局部更新,从而实现对私有训练数据的下游重构。这些发现表明,当局部聚合引发不对称观测时,仅靠SA并不能保证DFL中的隐私。

英文摘要

Secure Aggregation (SA) is widely regarded as a strong defense against model-update leakage in Federated Learning (FL), as it reveals only aggregate results while hiding individual updates. In Decentralized Federated Learning (DFL), SA is commonly instantiated as local neighborhood aggregation, where each node obtains a weighted aggregate over its neighbors. We show that this locality creates a structural leakage surface: sparse decentralized topologies provide colluding semi-honest nodes with asymmetric aggregate views, exposing multiple hidden linear combinations of honest participants' private states. Reconstructing private states from these aggregate views is fundamentally challenging, as both the private states and the aggregation coefficients are hidden. We tackle this challenge by establishing a formal connection to the Hidden Subset Sum Problem, a long-studied problem in cryptography. Building on this formulation, we design a lattice-based reconstruction approach that combines lattice reduction with structural filtering to reconstruct protected model states. We evaluate our attack on image, tabular, and text tasks under sparse DFL topologies. Our results show that colluding semi-honest nodes can recover the original local updates of honest nodes, enabling downstream reconstruction of private training data. These findings demonstrate that SA alone does not guarantee privacy in DFL when local aggregation induces asymmetric observations.

发表机构

  • Aalborg University(奥尔堡大学)
  • Institut Polytechnique de Paris(巴黎理工学院)

机构由 AI 辅助整理,请以论文原文为准。

↑