Where Does This Data Come from? Enhanced Source Inference Attacks in Federated Learning
Abstract
Federated learning (FL) enables collaborative model training without exposing raw data, offering a privacy-aware alternative to centralized learning. However, FL remains vulnerable to various privacy attacks that exploit shared model updates, including membership inference, property inference, and gradient inversion. Source inference attacks further threaten FL by identifying which client contributed a specific training sample, posing severe risks to user and institutional privacy. Existing source inference attacks mainly assume passive adversaries and overlook more realistic scenarios where the server actively manipulates the training process. In this paper, we present an enhanced source inference attack that demonstrates how a malicious server can amplify behavioral differences between clients to more accurately infer data origin. Our approach introduces active training manipulation and data augmentation to expose client-specific patterns. Experimental results across five representative FL algorithms and multiple datasets show that our method significantly outperforms prior passive attacks. These findings reveal a deeper level of privacy vulnerability in FL and call for stronger defense mechanisms under active threat models.
Cite
Text
Chen et al. "Where Does This Data Come from? Enhanced Source Inference Attacks in Federated Learning." International Joint Conference on Artificial Intelligence, 2025. doi:10.24963/IJCAI.2025/536Markdown
[Chen et al. "Where Does This Data Come from? Enhanced Source Inference Attacks in Federated Learning." International Joint Conference on Artificial Intelligence, 2025.](https://mlanthology.org/ijcai/2025/chen2025ijcai-data/) doi:10.24963/IJCAI.2025/536BibTeX
@inproceedings{chen2025ijcai-data,
title = {{Where Does This Data Come from? Enhanced Source Inference Attacks in Federated Learning}},
author = {Chen, Haiyang and Xu, Xiaolong and Zhu, Xiang and Zhou, Xiaokang and Dai, Fei and Gao, Yansong and Chen, Xiao and Wang, Shuo and Hu, Hongsheng},
booktitle = {International Joint Conference on Artificial Intelligence},
year = {2025},
pages = {4815-4823},
doi = {10.24963/IJCAI.2025/536},
url = {https://mlanthology.org/ijcai/2025/chen2025ijcai-data/}
}