{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/exploiting-unintended-feature-leakage-in","title":"Exploiting Unintended Feature Leakage in Collaborative Learning","arxiv_id":"1805.04049","date":"2018-05-10","proceeding":null,"authors":["Luca Melis","Congzheng Song","Emiliano De Cristofaro","Vitaly Shmatikov"],"abstract":"Collaborative machine learning and related techniques such as federated\nlearning allow multiple participants, each with his own training dataset, to\nbuild a joint model by training locally and periodically exchanging model\nupdates. We demonstrate that these updates leak unintended information about\nparticipants' training data and develop passive and active inference attacks to\nexploit this leakage. First, we show that an adversarial participant can infer\nthe presence of exact data points -- for example, specific locations -- in\nothers' training data (i.e., membership inference). Then, we show how this\nadversary can infer properties that hold only for a subset of the training data\nand are independent of the properties that the joint model aims to capture. For\nexample, he can infer when a specific person first appears in the photos used\nto train a binary gender classifier. We evaluate our attacks on a variety of\ntasks, datasets, and learning configurations, analyze their limitations, and\ndiscuss possible defenses.","url_abs":"http://arxiv.org/abs/1805.04049v3","url_pdf":"http://arxiv.org/pdf/1805.04049v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"exploiting-unintended-feature-leakage-in","repo_url":"https://github.com/csong27/property-inference-collaborative-ml","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok"}}],"tasks":[{"task_slug":"federated-learning","task_name":"Federated Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1805.04049","atlas_url":"https://app.syntology.ai/?focus=1805.04049","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}