跳到主要导航 跳到搜索 跳到主要内容

Casper: A Causality-Inspired Defense With Confounder Against Label Inference Attacks in Vertical Split Federated Learning

  • Meng Shen*
  • , Jin Meng
  • , Bohan Peng
  • , Xiangyun Tang
  • , Wei Wang
  • , Dusit Niyato
  • , Liehuang Zhu
  • *此作品的通讯作者
  • Beijing Institute of Technology
  • State Key Laboratory of Cryptology
  • Minzu University of China
  • Xi'an Jiaotong University
  • Nanyang Technological University

科研成果: 期刊稿件文章同行评审

摘要

Vertical Split Federated Learning (VSFL) allows participants to collaboratively train a better model with different features vertically partitioned in the same sample space, where the model is divided into bottom model and top model by the cut layer, trained by passive and active participants respectively. However, in the process, the labels owned by the active participant will still be inferred or stolen by curious or malicious passive participants. In this paper, we propose Casper, a causality-inspired defense mechanism with a confounder against label inference attacks in VSFL. Casper first analyzes the feasibility of optimizing the training process in VSFL at the intervention level from a causal perspective. It then introduces a confounder consisting of cut layer output reconstruction and label obfuscation to disrupt the direct causality between cut layer outputs and labels. Additionally, we integrate selective discrepancy training to further ensure model utility by strategically balancing training between active and passive participants. Extensive experiments conducted on four datasets across different tasks demonstrate that Casper effectively preserves label privacy while maintaining model performance, significantly outperforming current advanced defending methods in VSFL.

源语言英语
页(从-至)1050-1064
页数15
期刊IEEE Transactions on Information Forensics and Security
21
DOI
出版状态已出版 - 2026
已对外发布

学术指纹

探究 'Casper: A Causality-Inspired Defense With Confounder Against Label Inference Attacks in Vertical Split Federated Learning' 的科研主题。它们共同构成独一无二的学术指纹。

引用此