The Federation Strikes Back: A Survey of Federated Learning Privacy Attacks, Defenses, Applications, and Policy Landscape
arXiv:2405.03636 · doi:10.1145/3724113
Abstract
Deep learning has shown incredible potential across a wide array of tasks, and accompanied by this growth has been an insatiable appetite for data. However, a large amount of data needed for enabling deep learning is stored on personal devices, and recent concerns on privacy have further highlighted challenges for accessing such data. As a result, federated learning (FL) has emerged as an important privacy-preserving technology that enables collaborative training of machine learning models without the need to send the raw, potentially sensitive, data to a central server. However, the fundamental premise that sending model updates to a server is privacy-preserving only holds if the updates cannot be "reverse engineered" to infer information about the private training data. It has been shown under a wide variety of settings that this privacy premise does not hold. In this survey paper, we provide a comprehensive literature review of the different privacy attacks and defense methods in FL. We identify the current limitations of these attacks and highlight the settings in which the privacy of an FL client can be broken. We further dissect some of the successful industry applications of FL and draw lessons for future successful adoption. We survey the emerging landscape of privacy regulation for FL and conclude with future directions for taking FL toward the cherished goal of generating accurate models while preserving the privacy of the data from its participants.
Accepted to ACM Computing Surveys; 35 pages
References in corpus (19)
- I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences
- Do Gradient Inversion Attacks Make Federated Learning Unsafe?
- FastSecAgg: Scalable Secure Aggregation for Privacy-Preserving Federated Learning
- Federated Learning with Differential Privacy: Algorithms and Performance Analysis
- NVIDIA FLARE: Federated Learning from Simulation to Real-World
- FedML-HE: An Efficient Homomorphic-Encryption-Based Privacy-Preserving Federated Learning System
- Unlocking High-Accuracy Differentially Private Image Classification through Scale
- Papaya: Practical, Private, and Scalable Federated Learning
- When the Curious Abandon Honesty: Federated Learning Is Not Private
- Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification
- Tight Auditing of Differentially Private Machine Learning
- Federated Semi-Supervised Learning with Class Distribution Mismatch
- Federated Learning Priorities Under the European Union Artificial Intelligence Act
- Federated Action Recognition on Heterogeneous Embedded Devices
- Failure Prediction in Production Line Based on Federated Learning: An Empirical Study
- Beyond Gradients: Exploiting Adversarial Priors in Model Inversion Attacks
- Federated Learning of Gboard Language Models with Differential Privacy
- SwiftAgg: Communication-Efficient and Dropout-Resistant Secure Aggregation for Federated Learning with Worst-Case Security Guarantees
- How Much Privacy Does Federated Learning with Secure Aggregation Guarantee?