Skip to main navigation Skip to search Skip to main content

SLeak: Multi-Target Privacy Stealing Attack Against Split Learning

  • Xiaoyang Xu
  • , Wenzhe Yi
  • , Juan Wang
  • , Hongxin Hu
  • , Mengda Yang
  • , Ziang Li
  • , Yong Zhuang
  • , Yaxin Liu
  • , Mang Ye
  • Wuhan University

Research output: Contribution to journalArticlepeer-review

1 Scopus citations

Abstract

Split Learning (SL) is a distributed learning framework that has gained popularity for its privacy-preserving nature and low computational demands. However, recent studies have the potential that a server adversary to carry out inference attacks, compromising the privacy of victim clients. Nevertheless, upon re-evaluating prior studies, we found that existing methods rely on overly strong assumptions to enhance their performance, resulting in a significant decline in effectiveness under more realistic scenarios. In this work, we provide new insights into the inherent vulnerabilities of SL. Specifically, we discover that both the smashed data and the server model contain the client's representation preference, which the server adversary can exploit to build a substitute client that approximates the target client's unique feature extraction behavior. With a well-trained substitute client, the server can perfectly steal the target client's functionality, training data, and labels. Building on this observation, we introduce Split Leakage (SLeak), a new threat that targets multiple privacy stealing objectives against SL. Notably, SLeak does not depend on strong privacy priors and only requires partial same-domain auxiliary public data to conduct the attacks. Experimental results on diverse datasets and target models show that SLeak surpasses the state-of-the-art method across multiple metrics. Moreover, ablation studies further confirm its robustness and applicability under various scenarios and assumptions.

Original languageEnglish
Pages (from-to)5879-5891
Number of pages13
JournalIEEE Transactions on Pattern Analysis and Machine Intelligence
Volume48
Issue number5
DOIs
StatePublished - 2026

Keywords

  • Split learning
  • and computer vision
  • deep learning
  • privacy leakage
  • privacy stealing attack

Fingerprint

Dive into the research topics of 'SLeak: Multi-Target Privacy Stealing Attack Against Split Learning'. Together they form a unique fingerprint.

Cite this