Enhancing Privacy in Distributed Intelligent Vehicles with Information Bottleneck Theory

Xiangrui Xu,Pengrui Liu,Yiwen Zhao,Lei Han,Wei Wang,Yongsheng Zhu,Chongzhen Zhang,Bin Wang,Jian Shen,Zhen Han
DOI: https://doi.org/10.1109/jiot.2024.3434627
IF: 10.6
2024-01-01
IEEE Internet of Things Journal
Abstract:Vertical Federated Learning (VFL) shows promise for enabling collaborative learning among Internet-of-Vehicle systems (IoVs) without requiring the sharing of private training data. However, existing work has exposed VFL’s vulnerability to privacy-stealing attacks, where an honest but curious server might reconstruct a client’s raw data from client-uploaded embeddings. In this work, we first elucidate the intrinsic mechanisms of privacy attacks from an information theory perspective, which provides a solid foundation for potential defensive strategies. Based on our findings, we introduce PriVFL, a defense mechanism based on information bottleneck theory. PriVFL is designed to safeguard the privacy of VFL-based IoVs by enabling shared embeddings to extract minimal information from input data, while preserving the information essential to target labels. Specifically, PriVFL restricts the information contained in embeddings by reducing the upper bound of mutual information between the raw samples and embeddings uploaded from local clients. Meanwhile, PriVFL ensures the effectiveness of the model by increasing the mutual information lower bound between embeddings and samples’ labels. Our evaluation includes 5 benchmark datasets and 4 different models. Experimental results demonstrate that PriVFL effectively mitigates privacy attacks while preserving the model’s effectiveness. These findings underscore that PriVFL can significantly enhance the privacy of VFL-based IoVs, thereby bolstering the development of practical IoV applications.
What problem does this paper attempt to address?