Survey on Model Inversion Attack and Defense in Federated Learning

WANG Dong,QIN Qianqian,GUO Kaitian,LIU Rongke,YAN Weipeng,REN Yizhi,LUO Qingcai,SHEN Yanzhao
DOI: https://doi.org/10.11959/j.issn.1000-436x.2023209
2023-01-01
Abstract:As a distributed machine learning technology,federated learning can solve the problem of data islands.How-ever,because machine learning models will unconsciously remember training data,model parameters and global models uploaded by participants will suffer various privacy attacks.A systematic summary of existing attack methods was con-ducted for model inversion attacks in privacy attacks.Firstly,the theoretical framework of model inversion attack was summarized and analyzed in detail.Then,existing attack methods from the perspective of threat models were summa-rized,analyzed and compared.Then,the defense strategies of different technology types were summarized and compared.Finally,the commonly used evaluation criteria and datasets were summarized for inversion attack of existing models,and the main challenges and future research directions were summarized for inversion attack of models.
What problem does this paper attempt to address?