2607.07314v1 Jul 08, 2026 cs.LG

FedCVESA: 연관 값 인코딩 및 분할 집계를 통한 연합 학습에서의 학습 데이터 제거 기법

FedCVESA: Taking Away Training Data in Federated Learning via Correlation Value Encoding and Segmented Aggregation

Wenjian Luo
Wenjian Luo
Citations: 85
h-index: 5
Chongkai Li
Chongkai Li
Citations: 0
h-index: 0
Bang Zhang
Bang Zhang
Citations: 0
h-index: 0

연합 학습(FL)은 원시 데이터를 로컬 클라이언트에 유지하여 명시적인 데이터 노출을 방지하지만, 학습 과정과 학습된 모델 자체에서 여전히 개인 정보 보호 위험이 존재합니다. 최근 중앙 집중식 학습 데이터 제거 (TATD) 공격은 악의적인 학습이 심층 신경망의 기억 용량을 활용하여 학습 데이터를 저장하고 나중에 복구할 수 있음을 보여주었습니다. 그러나 이 기억 기반 위협은 다중 클라이언트를 사용하는 연합 학습 환경에서 체계적으로 연구되지 않았으며, 여기서 평균화 작업이 인코딩된 학습 데이터를 덮어쓸 수 있습니다. 본 논문에서는 악의적인 서버가 K명의 참여 클라이언트 중에서 n명의 대상 클라이언트를 선택하고 연합 학습 과정 동안 글로벌 모델에 개인 정보를 담은 학습 데이터를 적극적으로 삽입하는 화이트박스 TATD 공격을 연구합니다. 우리는 Pearson 상관 관계 정규화 항을 대상 클라이언트의 손실 함수에 추가하여, 개인 정보를 담은 학습 데이터가 선택된 모델 파라미터(캐리어 파라미터)에 점진적으로 인코딩되도록 하는 연합 학습 기반의 연관 값 인코딩 공격 (CVEA) 변형인 FedCVESA를 제안합니다. 또한, 서버 집계 과정에서 캐리어 파라미터가 덮어쓰여지는 것을 줄이기 위해 분산된 캐리어 파라미터에 대해 분할 집계를 수행하여 선택된 캐리어 파라미터를 보존하고 나머지 파라미터에 대해서는 표준 평균화를 적용합니다. Dirichlet 비-IID 분할을 사용한 MNIST, Fashion-MNIST 및 CIFAR-10 데이터셋에 대한 실험 결과, 제안된 방법은 학습된 모델에서 의미 있는 개인 정보를 가진 학습 이미지를 추출하면서도 제어된 개념 증명 환경에서 주요 작업의 유용성을 유지하는 것으로 나타났습니다. 이러한 결과는 연합 학습이 연구된 화이트박스 악의적인 서버 설정 하에서 적극적인 TATD 공격을 위한 파라미터 수준의 메모리 채널로 사용될 수 있음을 보여줍니다.

Original Abstract

Federated learning (FL) avoids explicit data exposure by keeping raw data on local clients, yet privacy risks remain in the training process and the learned model itself. Recently, centralized Taking Away Training Data (TATD) attacks have shown that malicious training could abuse the memorization capacity of deep models to store and later recover training data. However, this memorization-based threat has not been systematically studied under FL environments, where multi-client averaging could overwrite encoded training data. In this paper, we study a white-box TATD attack in which a malicious server selects n target clients from K participating clients and actively writes private training data into the global model during federated training. We propose FedCVESA, a federated variant of Correlation Value Encoding Attack (CVEA), by adding a Pearson-correlation regularizer to the loss function of target clients, so that private training data are gradually encoded into selected model parameters, referred to as carrier parameters. To reduce the overwriting of carrier parameters during server aggregation, we further propose segmented aggregation over dispersed carrier parameters, preserving selected carrier parameters while keeping standard averaging on the remaining parameters. Experiments on MNIST, Fashion-MNIST, and CIFAR-10 under Dirichlet non-IID partitions show that the proposed method can steal semantically meaningful private training images from the trained model while maintaining acceptable main-task utility in a controlled proof-of-concept setting. These results demonstrate that FL can become a parameter-level memorization channel for active TATD attack under the studied white-box malicious-server setting.

0 Citations
0 Influential
2.5 Altmetric
12.5 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!