-
Harvesting Private Medical Images in Federated Learning Systems with Crafted Models
Authors:
Shanghao Shi,
Md Shahedul Haque,
Abhijeet Parida,
Marius George Linguraru,
Y. Thomas Hou,
Syed Muhammad Anwar,
Wenjing Lou
Abstract:
Federated learning (FL) allows a set of clients to collaboratively train a machine-learning model without exposing local training samples. In this context, it is considered to be privacy-preserving and hence has been adopted by medical centers to train machine-learning models over private data. However, in this paper, we propose a novel attack named MediLeak that enables a malicious parameter serv…
▽ More
Federated learning (FL) allows a set of clients to collaboratively train a machine-learning model without exposing local training samples. In this context, it is considered to be privacy-preserving and hence has been adopted by medical centers to train machine-learning models over private data. However, in this paper, we propose a novel attack named MediLeak that enables a malicious parameter server to recover high-fidelity patient images from the model updates uploaded by the clients. MediLeak requires the server to generate an adversarial model by adding a crafted module in front of the original model architecture. It is published to the clients in the regular FL training process and each client conducts local training on it to generate corresponding model updates. Then, based on the FL protocol, the model updates are sent back to the server and our proposed analytical method recovers private data from the parameter updates of the crafted module. We provide a comprehensive analysis for MediLeak and show that it can successfully break the state-of-the-art cryptographic secure aggregation protocols, designed to protect the FL systems from privacy inference attacks. We implement MediLeak on the MedMNIST and COVIDx CXR-4 datasets. The results show that MediLeak can nearly perfectly recover private images with high recovery rates and quantitative scores. We further perform downstream tasks such as disease classification with the recovered data, where our results show no significant performance degradation compared to using the original training samples.
△ Less
Submitted 13 July, 2024;
originally announced July 2024.
-
Decentralized Spectrum Access System: Vision, Challenges, and a Blockchain Solution
Authors:
Yang Xiao,
Shanghao Shi,
Wenjing Lou,
Chonggang Wang,
Xu Li,
Ning Zhang,
Y. Thomas Hou,
Jeffrey H. Reed
Abstract:
Spectrum access system (SAS) is widely considered the de facto solution to coordinating dynamic spectrum sharing (DSS) and protecting incumbent users. The current SAS paradigm prescribed by the FCC for the CBRS band and standardized by the WInnForum follows a centralized service model in that a spectrum user subscribes to a SAS server for spectrum allocation service. This model, however, neither t…
▽ More
Spectrum access system (SAS) is widely considered the de facto solution to coordinating dynamic spectrum sharing (DSS) and protecting incumbent users. The current SAS paradigm prescribed by the FCC for the CBRS band and standardized by the WInnForum follows a centralized service model in that a spectrum user subscribes to a SAS server for spectrum allocation service. This model, however, neither tolerates SAS server failures (crash or Byzantine) nor resists dishonest SAS administrators, leading to serious concerns on SAS system reliability and trustworthiness. This is especially concerning for the evolving DSS landscape where an increasing number of SAS service providers and heterogeneous user requirements are coming up. To address these challenges, we propose a novel blockchain-based decentralized SAS architecture called BD-SAS that provides SAS services securely and efficiently, without relying on the trust of each individual SAS server for the overall system trustworthiness. In BD-SAS, a global blockchain (G-Chain) is used for spectrum regulatory compliance while smart contract-enabled local blockchains (L-Chains) are instantiated in individual spectrum zones for automating spectrum access assignment per user request. We hope our vision of a decentralized SAS, the BD-SAS architecture, and discussion on future challenges can open up a new direction towards reliable spectrum management in a decentralized manner.
△ Less
Submitted 10 December, 2021;
originally announced December 2021.
-
AoI-minimizing Scheduling in UAV-relayed IoT Networks
Authors:
Biplav Choudhury,
Vijay K. Shah,
Aidin Ferdowsi,
Jeffrey H. Reed,
Y. Thomas Hou
Abstract:
Due to flexibility, autonomy and low operational cost, unmanned aerial vehicles (UAVs), as fixed aerial base stations, are increasingly being used as \textit{relays} to collect time-sensitive information (i.e., status updates) from IoT devices and deliver it to the nearby terrestrial base station (TBS), where the information gets processed. In order to ensure timely delivery of information to the…
▽ More
Due to flexibility, autonomy and low operational cost, unmanned aerial vehicles (UAVs), as fixed aerial base stations, are increasingly being used as \textit{relays} to collect time-sensitive information (i.e., status updates) from IoT devices and deliver it to the nearby terrestrial base station (TBS), where the information gets processed. In order to ensure timely delivery of information to the TBS (from all IoT devices), optimal scheduling of time-sensitive information over two hop UAV-relayed IoT networks (i.e., IoT device to the UAV [hop 1], and UAV to the TBS [hop 2]) becomes a critical challenge. To address this, we propose scheduling policies for Age of Information (AoI) minimization in such two-hop UAV-relayed IoT networks. To this end, we present a low-complexity MAF-MAD scheduler, that employs Maximum AoI First (MAF) policy for sampling of IoT devices at UAV (hop 1) and Maximum AoI Difference (MAD) policy for updating sampled packets from UAV to the TBS (hop 2). We show that MAF-MAD is the optimal scheduler under ideal conditions, i.e., error-free channels and generate-at-will traffic generation at IoT devices. On the contrary, for realistic conditions, we propose a Deep-Q-Networks (DQN) based scheduler. Our simulation results show that DQN-based scheduler outperforms MAF-MAD scheduler and three other baseline schedulers, i.e., Maximal AoI First (MAF), Round Robin (RR) and Random, employed at both hops under general conditions when the network is small (with 10's of IoT devices). However, it does not scale well with network size whereas MAF-MAD outperforms all other schedulers under all considered scenarios for larger networks.
△ Less
Submitted 24 September, 2021; v1 submitted 11 July, 2021;
originally announced July 2021.
-
A Real-Time mmWave Communication Testbed with Phase Noise Cancellation
Authors:
Adnan Quadri,
Huacheng Zeng,
Y. Thomas Hou
Abstract:
As the spectrum under 6 GHz is being depleted, pushing wireless communications onto millimeter wave (mmWave) frequencies is a trend that promises multi-Gbps data rate. mmWave is therefore considered as a key technology for 5G wireless systems and has attracted tremendous research efforts. The booming research on mmWave necessitates a reconfigurable mmWave testbed that can be used to prototype and…
▽ More
As the spectrum under 6 GHz is being depleted, pushing wireless communications onto millimeter wave (mmWave) frequencies is a trend that promises multi-Gbps data rate. mmWave is therefore considered as a key technology for 5G wireless systems and has attracted tremendous research efforts. The booming research on mmWave necessitates a reconfigurable mmWave testbed that can be used to prototype and validate new research ideas in real wireless environments. In this paper, we develop an easy-to-use mmWave testbed using commercial off-the-shelf devices (USRP and 60 GHz Tx/Rx RF frontends) and open-source software package (GNU Radio). A key component of our testbed is a phase noise cancellation (PNC) scheme, which can significantly reduce the phase noise at the receiver by leveraging the pilot signal inserted at the transmitter. We have implemented a simplified version of IEEE 802.11 PHY on this mmWave testbed. Experimental results show that, with the PNC scheme, our testbed can achieve -20 dB EVM data transmission for real-time video streaming.
△ Less
Submitted 13 July, 2019;
originally announced July 2019.