Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Make Split, not Hijack: Preventing Feature-Space Hijacking Attacks in Split Learning
Tampere University, Finland.
Tampere University, Finland.ORCID-id: 0000-0002-1913-7985
RISE Research Institutes of Sweden, Digitala system, Datavetenskap. Tampere University, Finland.
2024 (engelsk)Inngår i: Proceedings of the 29th ACM Symposium on Access Control Models and Technologies, Association for Computing Machinery (ACM) , 2024, s. 19-30Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

The popularity of Machine Learning (ML) makes the privacy of sensitive data more imperative than ever. Collaborative learning techniques like Split Learning (SL) aim to protect client data while enhancing ML processes. Though promising, SL has been proved to be vulnerable to a plethora of attacks, thus raising concerns about its effectiveness on data privacy. In this work, we introduce a hybrid approach combining SL and Function Secret Sharing (FSS) to ensure client data privacy. The client adds a random mask to the activation map before sending it to the servers. The servers cannot access the original function but instead work with shares generated using FSS. Consequently, during both forward and backward propagation, the servers cannot reconstruct the client’s raw data from the activation map. Furthermore, through visual invertibility, we demonstrate that the server is incapable of reconstructing the raw image data from the activation map when using FSS. It enhances privacy by reducing privacy leakage compared to other SL-based approaches where the server can access client input information. Our approach also ensures security against feature space hijacking attack, protecting sensitive information from potential manipulation. Our protocols yield promising results, reducing communication overhead by over 2× and training time by over 7× compared to the same model with FSS, without any SL. Also, we show that our approach achieves > 96% accuracy and remains equivalent to the plaintext models. 

sted, utgiver, år, opplag, sider
Association for Computing Machinery (ACM) , 2024. s. 19-30
Emneord [en]
Chemical activation, Privacy-preserving techniques, Sensitive data, Activation maps, Collaborative learning, Feature space, Function secret sharing, Learning techniques, Machine-learning, Privacy, Secret-sharing, Sensitive datas, Split learning, Machine learning
HSV kategori
Identifikatorer
URN: urn:nbn:se:ri:diva-74716DOI: 10.1145/3649158.3657039Scopus ID: 2-s2.0-85197783248ISBN: 9798400704918 (tryckt)OAI: oai:DiVA.org:ri-74716DiVA, id: diva2:1887557
Konferanse
The 29th ACM Symposium on Access Control Models and Technologies
Forskningsfinansiär
EU, Horizon Europe, 101069535
Merknad

Conference name: 29th ACM Symposium on Access Control Models and Technologies, SACMAT 2024; Conference date: 15 May 2024 through 17 May 2024; Conference code: 200615; All Open Access, Hybrid Gold Open Access

This work was funded by the HARPOCRATES EU research project (No. 101069535) and the Technology Innovation Institute (TII), UAE, for the project ARROWSMITH.

Tilgjengelig fra: 2024-08-08 Laget: 2024-08-08 Sist oppdatert: 2025-09-23bibliografisk kontrollert

Open Access i DiVA

fulltext(1818 kB)69 nedlastinger
Filinformasjon
Fil FULLTEXT01.pdfFilstørrelse 1818 kBChecksum SHA-512
1cb4d8fed117397f34e9db6d88734fe1551def67f6de559e2441dda86f0921c06924253ee3dbab1cb74ef27e8ace512e549f74825c97e284aa583345226ee75d
Type fulltextMimetype application/pdf

Andre lenker

Forlagets fulltekstScopus

Søk i DiVA

Av forfatter/redaktør
Budzys, Mindaugas
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar
Totalt: 70 nedlastinger
Antall nedlastinger er summen av alle nedlastinger av alle fulltekster. Det kan for eksempel være tidligere versjoner som er ikke lenger tilgjengelige

doi
isbn
urn-nbn

Altmetric

doi
isbn
urn-nbn
Totalt: 479 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
v. 2.47.0