Cargando…
FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems
In traditional centralized Android malware classifiers based on machine learning, the training sample uploaded by users contains sensitive personal information, such as app usage and device security status, which will undermine personal privacy if used directly by the server. Federated-learning-base...
Autores principales: | , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
MDPI
2023
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10378591/ https://www.ncbi.nlm.nih.gov/pubmed/37510000 http://dx.doi.org/10.3390/e25071053 |
_version_ | 1785079805784358912 |
---|---|
author | Jiang, Changnan Xia, Chunhe Liu, Zhuodong Wang, Tianbo |
author_facet | Jiang, Changnan Xia, Chunhe Liu, Zhuodong Wang, Tianbo |
author_sort | Jiang, Changnan |
collection | PubMed |
description | In traditional centralized Android malware classifiers based on machine learning, the training sample uploaded by users contains sensitive personal information, such as app usage and device security status, which will undermine personal privacy if used directly by the server. Federated-learning-based Android malware classifiers have attracted much attention due to their privacy-preserving and multi-party joint modeling. However, research shows that indirect privacy inferences from curious central servers threaten this framework. We propose a privacy risk evaluation framework, FedDroidMeter, based on normalized mutual information in response to user privacy requirements to measure the privacy risk in FL-based malware classifiers. It captures the essential cause of the disclosure of sensitive information in classifiers, independent of the attack model and capability. We performed numerical assessments using the Androzoo dataset, the baseline FL-based classifiers, the privacy-inferred attack model, and the baseline methodology of privacy evaluation. The experimental results show that FedDroidMeter can measure the privacy risks of the classifiers more effectively. Meanwhile, by comparing different models, FL, and privacy parameter settings, we proved that FedDroidMeter could compare the privacy risk between different use cases equally. Finally, we preliminarily study the law of privacy risk in classifiers. The experimental results emphasize the importance of providing a systematic privacy risk evaluation framework for FL-based malware classifiers and provide experience and a theoretical basis for studying targeted defense methods. |
format | Online Article Text |
id | pubmed-10378591 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2023 |
publisher | MDPI |
record_format | MEDLINE/PubMed |
spelling | pubmed-103785912023-07-29 FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems Jiang, Changnan Xia, Chunhe Liu, Zhuodong Wang, Tianbo Entropy (Basel) Article In traditional centralized Android malware classifiers based on machine learning, the training sample uploaded by users contains sensitive personal information, such as app usage and device security status, which will undermine personal privacy if used directly by the server. Federated-learning-based Android malware classifiers have attracted much attention due to their privacy-preserving and multi-party joint modeling. However, research shows that indirect privacy inferences from curious central servers threaten this framework. We propose a privacy risk evaluation framework, FedDroidMeter, based on normalized mutual information in response to user privacy requirements to measure the privacy risk in FL-based malware classifiers. It captures the essential cause of the disclosure of sensitive information in classifiers, independent of the attack model and capability. We performed numerical assessments using the Androzoo dataset, the baseline FL-based classifiers, the privacy-inferred attack model, and the baseline methodology of privacy evaluation. The experimental results show that FedDroidMeter can measure the privacy risks of the classifiers more effectively. Meanwhile, by comparing different models, FL, and privacy parameter settings, we proved that FedDroidMeter could compare the privacy risk between different use cases equally. Finally, we preliminarily study the law of privacy risk in classifiers. The experimental results emphasize the importance of providing a systematic privacy risk evaluation framework for FL-based malware classifiers and provide experience and a theoretical basis for studying targeted defense methods. MDPI 2023-07-12 /pmc/articles/PMC10378591/ /pubmed/37510000 http://dx.doi.org/10.3390/e25071053 Text en © 2023 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). |
spellingShingle | Article Jiang, Changnan Xia, Chunhe Liu, Zhuodong Wang, Tianbo FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems |
title | FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems |
title_full | FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems |
title_fullStr | FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems |
title_full_unstemmed | FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems |
title_short | FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems |
title_sort | feddroidmeter: a privacy risk evaluator for fl-based android malware classification systems |
topic | Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10378591/ https://www.ncbi.nlm.nih.gov/pubmed/37510000 http://dx.doi.org/10.3390/e25071053 |
work_keys_str_mv | AT jiangchangnan feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems AT xiachunhe feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems AT liuzhuodong feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems AT wangtianbo feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems |