Cargando…

FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems

In traditional centralized Android malware classifiers based on machine learning, the training sample uploaded by users contains sensitive personal information, such as app usage and device security status, which will undermine personal privacy if used directly by the server. Federated-learning-base...

Descripción completa

Detalles Bibliográficos
Autores principales: Jiang, Changnan, Xia, Chunhe, Liu, Zhuodong, Wang, Tianbo
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10378591/
https://www.ncbi.nlm.nih.gov/pubmed/37510000
http://dx.doi.org/10.3390/e25071053
_version_ 1785079805784358912
author Jiang, Changnan
Xia, Chunhe
Liu, Zhuodong
Wang, Tianbo
author_facet Jiang, Changnan
Xia, Chunhe
Liu, Zhuodong
Wang, Tianbo
author_sort Jiang, Changnan
collection PubMed
description In traditional centralized Android malware classifiers based on machine learning, the training sample uploaded by users contains sensitive personal information, such as app usage and device security status, which will undermine personal privacy if used directly by the server. Federated-learning-based Android malware classifiers have attracted much attention due to their privacy-preserving and multi-party joint modeling. However, research shows that indirect privacy inferences from curious central servers threaten this framework. We propose a privacy risk evaluation framework, FedDroidMeter, based on normalized mutual information in response to user privacy requirements to measure the privacy risk in FL-based malware classifiers. It captures the essential cause of the disclosure of sensitive information in classifiers, independent of the attack model and capability. We performed numerical assessments using the Androzoo dataset, the baseline FL-based classifiers, the privacy-inferred attack model, and the baseline methodology of privacy evaluation. The experimental results show that FedDroidMeter can measure the privacy risks of the classifiers more effectively. Meanwhile, by comparing different models, FL, and privacy parameter settings, we proved that FedDroidMeter could compare the privacy risk between different use cases equally. Finally, we preliminarily study the law of privacy risk in classifiers. The experimental results emphasize the importance of providing a systematic privacy risk evaluation framework for FL-based malware classifiers and provide experience and a theoretical basis for studying targeted defense methods.
format Online
Article
Text
id pubmed-10378591
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-103785912023-07-29 FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems Jiang, Changnan Xia, Chunhe Liu, Zhuodong Wang, Tianbo Entropy (Basel) Article In traditional centralized Android malware classifiers based on machine learning, the training sample uploaded by users contains sensitive personal information, such as app usage and device security status, which will undermine personal privacy if used directly by the server. Federated-learning-based Android malware classifiers have attracted much attention due to their privacy-preserving and multi-party joint modeling. However, research shows that indirect privacy inferences from curious central servers threaten this framework. We propose a privacy risk evaluation framework, FedDroidMeter, based on normalized mutual information in response to user privacy requirements to measure the privacy risk in FL-based malware classifiers. It captures the essential cause of the disclosure of sensitive information in classifiers, independent of the attack model and capability. We performed numerical assessments using the Androzoo dataset, the baseline FL-based classifiers, the privacy-inferred attack model, and the baseline methodology of privacy evaluation. The experimental results show that FedDroidMeter can measure the privacy risks of the classifiers more effectively. Meanwhile, by comparing different models, FL, and privacy parameter settings, we proved that FedDroidMeter could compare the privacy risk between different use cases equally. Finally, we preliminarily study the law of privacy risk in classifiers. The experimental results emphasize the importance of providing a systematic privacy risk evaluation framework for FL-based malware classifiers and provide experience and a theoretical basis for studying targeted defense methods. MDPI 2023-07-12 /pmc/articles/PMC10378591/ /pubmed/37510000 http://dx.doi.org/10.3390/e25071053 Text en © 2023 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Jiang, Changnan
Xia, Chunhe
Liu, Zhuodong
Wang, Tianbo
FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems
title FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems
title_full FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems
title_fullStr FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems
title_full_unstemmed FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems
title_short FedDroidMeter: A Privacy Risk Evaluator for FL-Based Android Malware Classification Systems
title_sort feddroidmeter: a privacy risk evaluator for fl-based android malware classification systems
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10378591/
https://www.ncbi.nlm.nih.gov/pubmed/37510000
http://dx.doi.org/10.3390/e25071053
work_keys_str_mv AT jiangchangnan feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems
AT xiachunhe feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems
AT liuzhuodong feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems
AT wangtianbo feddroidmeteraprivacyriskevaluatorforflbasedandroidmalwareclassificationsystems