跳到主要导航 跳到搜索 跳到主要内容

Label Inference Attacks Against Federated Unlearning

  • Wei Wang
  • , Xiangyun Tang*
  • , Yajie Wang*
  • , Yijing Lin
  • , Tao Zhang
  • , Meng Shen
  • , Dusit Niyato
  • , Liehuang Zhu
  • *此作品的通讯作者
  • Minzu University of China
  • Beijing Institute of Technology
  • Beijing University of Posts and Telecommunications
  • Beijing Jiaotong University
  • Nanyang Technological University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Federated Unlearning (FU) has emerged as a promising solution to respond to “the right to be forgotten” of clients, by allowing clients to erase their data from global models without compromising model performance. Unfortunately, researchers find that the parameter variations of models induced by FU expose clients’ data information, enabling attackers to infer the label of unlearning data, while label inference attacks against FU remain unexplored. In this paper, we introduce and analyze a new privacy threat against FU and propose a novel label inference attack, ULIA, which can infer unlearning data labels across three FU levels. To address the unique challenges of inferring labels via the models variations, we design a gradient-label mapping mechanism in ULIA that establishes a relationship between gradient variations and unlearning labels, enabling inferring labels on accumulated model variations. We evaluate ULIA on both IID and non-IID settings. Experimental results show that in the IID setting, ULIA achieves a 100% Attack Success Rate (ASR) under both class-level and client-level unlearning. Even when only 1% of a user’s local data is forgotten, ULIA still attains an ASR ranging from 93% to 62.3%.

源语言英语
主期刊名Knowledge Science, Engineering and Management - 18th International Conference, KSEM 2025, Proceedings
编辑Tianqing Zhu, Wanlei Zhou, Congcong Zhu
出版商Springer Science and Business Media Deutschland GmbH
1-16
页数16
ISBN(印刷版)9789819530007
DOI
出版状态已出版 - 2026
已对外发布
活动18th International Conference on Knowledge Science, Engineering and Management KSEM 2025 - Macao, 中国
期限: 4 8月 20257 8月 2025

丛书

姓名Lecture Notes in Computer Science
15919 LNAI
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议18th International Conference on Knowledge Science, Engineering and Management KSEM 2025
国家/地区中国
Macao
时期4/08/257/08/25

学术指纹

探究 'Label Inference Attacks Against Federated Unlearning' 的科研主题。它们共同构成独一无二的学术指纹。

引用此