MvSMIA: Multi-view Source Membership Inference Attack in Federated Learning
摘要
Federated Learning has made significant progress in enhancing data privacy and security, but it still faces security risks from Source Membership Inference Attacks. Existing methods have limitations in terms of attack efficiency and practicality, and they fail to fully exploit the potential information of sample loss during model training. To address these issues, we propose a loss-based multi-view source membership inference attack method. This method fully leverages the loss differences between member and non-member samples in the model output, as well as the multi-dimensional synergistic analysis of sample loss in both horizontal and vertical directions during training, to carry out the attack without violating the predefined federated learning protocol. Experiments on three publicly available datasets demonstrate that the proposed method achieves higher attack success rates. Finally, the experiments also explore the factors influencing the attack success rate.