notesum.ai
Published at November 27Hidden Data Privacy Breaches in Federated Learning
cs.CL
cs.CR
Released Date: November 27, 2024
Authors: Xueluan Gong1, Yuji Wang2, Shuaike Li3, Mengyuan Sun3, Songze Li4, Qian Wang3, Kwok-Yan Lam1, Chen Chen1
Aff.: 1Nanyang Technological University, Singapore; 2Shanghai Jiao Tong University, China; 3Wuhan University, China; 4Southeast University, China

| CIFAR-10 dataset | |||||||
|---|---|---|---|---|---|---|---|
| Baselines | Metrics† | ||||||
| Transpose Attack | Leakage () | 8.2 4.0 | 2.4 2.0 | 0.6 0.8 | 0.2 0.4 | 0.0 0.0 | 0.0 0.0 |
| SSIM () | 0.506 0.034 | 0.394 0.023 | 0.306 0.037 | 0.250 0.035 | 0.197 0.019 | 0.151 0.010 | |
| PSNR () | 15.994 0.441 | 14.882 0.385 | 14.378 0.387 | 13.983 0.559 | 13.504 0.319 | 13.103 0.330 | |
| LPIPS () | 0.457 0.010 | 0.490 0.021 | 0.518 0.013 | 0.547 0.010 | 0.548 0.007 | 0.557 0.009 | |
| RtF | Leakage () | 11.5 0.3 | 11.2 1.1 | 4.2 0.6 | 1.6 0.2 | 0.7 ± 0.3 | 1.4 ± 0.3 |
| SSIM () | 0.670 0.018 | 0.407 0.023 | 0.198 0.013 | 0.070 0.007 | 0.195 ± 0.049 | 0.280 ± 0.036 | |
| PSNR () | 19.931 0.417 | 13.115 0.456 | 8.848 0.293 | 6.358 0.116 | 7.885 ± 0.939 | 8.601 ± 0.688 | |
| LPIPS () | 0.205 0.015 | 0.390 0.018 | 0.521 0.007 | 0.577 0.007 | 0.504 ± 0.042 | 0.485 ± 0.023 | |
| LOKI | Leakage () | 13.8 0.4 | 27.5 0.5 | 55.6 0.9 | 110.0 0.7 | 219.080 0.9 | 435.6 4.6 |
| SSIM () | 0.870 0.019 | 0.849 0.015 | 0.800 0.015 | 0.739 0.006 | 0.696 0.006 | 0.700 0.015 | |
| PSNR () | 32.095 1.32 | 31.400 0.960 | 29.471 0.890 | 27.269 0.127 | 25.903 0.198 | 26.173 0.725 | |
| LPIPS () | 0.071 0.011 | 0.086 0.010 | 0.114 0.009 | 0.151 0.004 | 0.177 0.004 | 0.173 0.008 | |
| our method | Leakage () | 16.0 0.0 | 32.0 0.0 | 64.0 0.0 | 128.0 0.0 | 256.0 0.0 | 512.0 0.0 |
| SSIM () | 1.000 0.000 | 1.000 0.000 | 1.000 0.000 | 0.999 0.001 | 0.934 0.015 | 0.785 0.021 | |
| PSNR () | 68.734 0.465 | 67.565 0.446 | 64.764 0.711 | 59.978 1.394 | 30.394 0.778 | 23.122 0.130 | |
| LPIPS () | 0.000 0.000 | 0.000 0.000 | 0.000 0.000 | 0.001 0.001 | 0.093 0.019 | 0.295 0.021 | |
| CIFAR-100 dataset | |||||||
| Baselines | Metrics† | ||||||
| Transpose Attack | Leakage () | 3.8 2.6 | 3.8 3.4 | 3.4 2.1 | 5.4 2.4 | 9.4 2.3 | 7.2 1.9 |
| SSIM () | 0.388 0.053 | 0.301 0.047 | 0.248 0.018 | 0.224 0.014 | 0.215 0.016 | 0.190 0.009 | |
| PSNR () | 15.582 0.921 | 14.463 0.494 | 13.896 0.383 | 13.725 0.186 | 13.590 0.223 | 13.348 0.070 | |
| LPIPS () | 0.475 0.018 | 0.499 0.017 | 0.528 0.007 | 0.533 0.004 | 0.549 0.009 | 0.559 0.012 | |
| RtF | Leakage () | 11.3 0.3 | 11.6 1.3 | 5.0 0.3 | 2.7 0.4 | 0.9 ± 0.2 | 1.6 ± 0.2 |
| SSIM () | 0.655 0.028 | 0.421 0.027 | 0.209 0.010 | 0.106 0.012 | 0.229 ± 0.026 | 0.297 ± 0.034 | |
| PSNR () | 19.656 0.779 | 13.784 0.588 | 8.860 0.261 | 6.820 0.245 | 7.446 ± 0.820 | 9.075 ± 1.139 | |
| LPIPS () | 0.213 0.016 | 0.371 0.018 | 0.521 0.006 | 0.570 0.006 | 0.522 ± 0.011 | 0.475 ± 0.007 | |
| LOKI | Leakage () | 13.6 1.0 | 26.6 1.4 | 54.8 2.4 | 113.6 3.4 | 221.8 5.9 | 432.4 8.6 |
| SSIM () | 0.856 0.074 | 0.854 0.046 | 0.794 0.037 | 0.740 0.042 | 0.701 0.024 | 0.705 0.024 | |
| PSNR () | 33.282 6.744 | 31.572 3.341 | 27.907 2.039 | 26.638 2.045 | 26.026 1.137 | 5.810 0.888 | |
| LPIPS () | 0.073 0.043 | 0.083 0.024 | 0.125 0.021 | 0.155 0.029 | 0.182 0.014 | 0.180 0.016 | |
| Ours | Leakage () | 16.0 0.0 | 32.0 0.0 | 64.0 0.0 | 128.0 0.0 | 256.0 0.0 | 505.8 5.19 |
| SSIM () | 1.000 0.000 | 1.000 0.000 | 1.000 0.000 | 0.999 0.001 | 0.920 0.014 | 0.702 0.034 | |
| PSNR () | 68.520 0.887 | 65.489 0.431 | 62.697 0.230 | 56.803 0.815 | 29.916 0.619 | 22.281 0.436 | |
| LPIPS () | 0.000 0.000 | 0.000 0.000 | 0.000 0.000 | 0.001 0.001 | 0.102 0.016 | 0.340 0.021 | |