Security and Privacy in Federated Learning
Book information
Description
In this book, the authors highlight the latest research findings on the security and privacy of federated learning systems. The main attacks and counterattacks in this booming field are presented to readers in connection with inference, poisoning, generative adversarial networks, differential privacy, secure multi-party computation, homomorphic encryption, and shuffle, respectively. The book offers an essential overview for researchers who are new to the field, while also equipping them to explore this “uncharted territory.” For each topic, the authors first present the key concepts, followed by the most important issues and solutions, with appropriate references for further reading. The book is self-contained, and all chapters can be read independently. It offers a valuable resource for master’s students, upper undergraduates, Ph.D. students, and practicing engineers alike. Preface Acknowledgments Contents 1 Introduction to Federated Learning 1.1 Federated Learning Paradigm 1.1.1 Deep Learning 1.1.2 Federated Learning 1.1.3 Categories of Federated Learning 1.1.4 Challenges in Federated Learning 1.2 Security and Privacy in Federated Learning 1.2.1 Source of Vulnerabilities 1.2.2 Attacks in Federated Learning 1.2.3 Defense Techniques in Federated Learning 1.3 Structure of the Book 2 Inference Attacks and Counterattacks in Federated Learning 2.1 What Is Inference Attack? 2.2 Inference Attack Categories 2.3 Threat from Inference Attacks 2.4 Inference Attacks in Federated Learning 2.4.1 Model Inversion Attacks 2.4.2 Property Inference Attacks 2.4.3 Membership Inference Attacks 2.4.4 Model Inference Attacks 2.5 Counter-Inference Attacks 2.6 Summary of the Chapter 3 Poisoning Attacks and Counterattacks in Federated Learning 3.1 What Is Poisoning Attack? 3.2 Poisoning Attack Basics 3.3 Classification of Poisoning Attacks 3.3.1 Untargeted Poisoning Attacks 3.3.2 Targeted Poisoning Attacks 3.3.3 Backdoor Poisoning Attacks 3.4 Techniques for Poisoning Attacks 3.4.1 Label Manipulation 3.4.2 Data Manipulation 3.4.3 Other Technologies 3.5 Poisoning Attacks in Federated Learning 3.5.1 The Basics of Poisoning Attacks in Federated Learning 3.5.2 Efficiency and Stealth of Poisoning Attacks in Federated Learning 3.6 Counter Poisoning Attacks in Federated Learning 3.6.1 Counterattacks from Data Perspective 3.6.2 Counterattacks from Behavior Perspective 3.6.3 Other Countermeasures 3.7 Summary of the Chapter 4 GAN Attacks and Counterattacks in Federated Learning 4.1 What Are Generative Adversarial Networks (GANs) 4.2 The Original GAN 4.2.1 Architecture and Working Flow 4.2.2 Games and Objective Functions 4.3 Variants of GAN 4.3.1 Conditional GAN 4.3.2 InfoGAN 4.3.3 Deep Convolutional GAN 4.3.4 WGAN 4.4 GAN-Based Attacks in Federated Learning 4.4.1 GAN-Based Security Threats 4.4.2 GAN-Based Poisoning Attacks 4.4.2.1 GAN-Based Poisoning Attacks in Federated Learning 4.4.3 GAN-Based Privacy Threats 4.4.3.1 GAN-Based Inference Attacks 4.4.3.2 GAN-Based Inference Attacks in Federated Learning 4.4.4 GAN-Based Attacks from Insiders 4.4.5 GAN-Based Attacks from Clients 4.4.6 GAN-Based Attacks from Central Server 4.4.7 GAN-Based Attacks from Outsiders 4.5 Counter GAN-Based Attacks 4.5.1 Passive Defense Against GAN-Based Attacks 4.5.2 Active Defense Against GAN-Based Attacks 4.6 Summary of the Chapter 5 Differential Privacy in Federated Learning 5.1 What Is Differential Privacy? 5.2 Differential Privacy Definition and Terms 5.2.1 Mathematical Model of Differential Privacy 5.2.2 Differential Privacy Using Laplace Noise 5.2.3 Differential Privacy Using Gaussian Noise 5.3 Differential Privacy in Federated Learning 5.4 Main Differential Privacy Methods in Federated Learning 5.4.1 Centralized Differential Privacy 5.4.2 Local Differential Privacy 5.4.3 Distributed Differential Privacy 5.5 Application of Differential Privacy in Federated Learning 5.5.1 The Applications of Variant Differential Privacy 5.5.2 The Combination of Differential Privacy and Other Methods 5.6 Future Discussion 5.6.1 Reduce the Cost of Privacy Protection 5.6.2 Customized Privacy Restrictions 5.7 Summary of the Chapter 6 Secure Multi-party Computation in Federated Learning 6.1 What Is Secure Multi-party Computation 6.2 Building Blocks for Secure Multi-party Computing 6.2.1 Oblivious Transfer 6.2.2 Garbled Circuit 6.2.3 Secret Sharing 6.2.4 Homomorphic Encryption 6.2.5 Trusted Execution Environment 6.3 Secure Multi-party Computation in Federated Learning 6.3.1 Masking for Data Aggregation 6.3.2 Secret Sharing in Federated Learning 6.4 Summary of the Chapter 7 Secure Data Aggregation in Federated Learning 7.1 What Is Homomorphic Encryption 7.2 Popular Homomorphic Encryption Schemes in Federated Learning 7.2.1 The Paillier Scheme 7.2.2 The ElGamal Scheme 7.2.3 The Goldwasser–Micali Scheme 7.3 Homomorphic Encryption for Data Aggregation in Federated Learning 7.3.1 Multiple Server Data Aggregation 7.3.2 Zero Knowledge Proof of Data Aggregation 7.4 Verification of Data Aggregation 7.5 Summary of the Chapter 8 Anonymous Communication and Shuffle Model in Federated Learning 8.1 What Is Anonymous Communication? 8.2 Onion Routing and Tor 8.3 The Shuffle Model 8.4 Privacy Amplification in Federated Learning 8.5 Anonymous Communication and Shuffle Model in Federated Learning 8.6 Summary of the Chapter 9 The Future Work 9.1 The Related Landscape in the Near Future 9.2 The Challenges on Security in the Near Future 9.2.1 Existing Attacks 9.2.2 Digital Forensics 9.2.3 New Attacks 9.3 The Challenges on Privacy in the Near Future 9.3.1 Privacy Measurement 9.3.2 Big Data Modelling 9.3.3 Privacy Tools 9.3.4 Personalized Privacy 9.3.5 AI Ethics 9.4 Summary of the Chapter References
Similar books
Privacy Preservation in IoT: Machine Learning Approaches: A Comprehensive Survey and Use Cases (SpringerBriefs in Computer Science)
Machine Learning Empowered Intelligent Data Center Networking. Evolution, Challenges and Opportunities
2023 · PDF
Machine Learning Empowered Intelligent Data Center Networking: Evolution, Challenges and Opportunities
2023 · PDF
Security and Privacy in Digital Economy: First International Conference, SPDE 2020, Quzhou, China, October 30 – November 1, 2020, Proceedings
2020 · PDF
Security and Privacy in Digital Economy
2020 · PDF
Malicious Attack Propagation and Source Identification
2019 · PDF
Big Data Concepts, Theories, and Applications
2016 · PDF
Networking for Big Data
2015 · PDF