Pith. sign in

REVIEW 1 cited by

Similarity-based Label Inference Attack against Training and Inference of Split Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2203.05222 v2 pith:OCIP54PO submitted 2022-03-10 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords learninginferencelabelsplitdataresultssimilaritytraining
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Split learning is a promising paradigm for privacy-preserving distributed learning. The learning model can be cut into multiple portions to be collaboratively trained at the participants by exchanging only the intermediate results at the cut layer. Understanding the security performance of split learning is critical for many privacy-sensitive applications. This paper shows that the exchanged intermediate results, including the smashed data (i.e., extracted features from the raw data) and gradients during training and inference of split learning, can already reveal the private labels. We mathematically analyze the potential label leakages and propose the cosine and Euclidean similarity measurements for gradients and smashed data, respectively. Then, the two similarity measurements are shown to be unified in Euclidean space. Based on the similarity metric, we design three label inference attacks to efficiently recover the private labels during both the training and inference phases. Experimental results validate that the proposed approaches can achieve close to 100% accuracy of label attacks. The proposed attack can still achieve accurate predictions against various state-of-the-art defense mechanisms, including DP-SGD, label differential privacy, gradient compression, and Marvell.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split Learning (Full Version)

    cs.CR 2025-01 conditional novelty 6.0 of 10

    SafeSplit detects poisoned client updates in U-shaped split learning by comparing DCT frequency distances and rotational distances of backbone states, then rolling back to the latest benign checkpoint; experiments sho...

Pith tools