Label Leakage and Protection in Two-party Split Learning

Oscar LiJiankai SunXin YangWeihao GaoHongyi ZhangJunyuan XieVirginia SmithChong Wang

article2022ICLR170 citations

Exposes how adversaries can reconstruct private labels in two-party split learning and develops Marvell, an optimized perturbation defense that minimizes worst-case label leakage while preserving model utility.

Listen

Modern privacy regulations and competitive concerns make it critical for organizations to collaborate on machine learning without sharing proprietary raw data or sensitive target labels, such as user purchase conversions or medical diagnoses. Two-party split learning is widely viewed as a privacy-preserving framework because organizations split a deep neural network across intermediate model layers and exchange only intermediate outputs and gradients rather than raw records. However, because each transmitted gradient corresponds to an aligned, specific data record, standard aggregate privacy defenses like differential privacy cannot be applied directly. This raises an urgent question regarding whether communicating cut-layer gradients unintentionally reveals the proprietary target labels.

The article evaluates the vulnerability of two-party split learning to private label theft during model training, quantifies this privacy loss, and develops principled noise-perturbation defenses to safeguard sensitive labels without degrading model utility.

To investigate this issue, the authors formalize a threat model involving an honest-but-curious non-label party seeking to reconstruct the other party's binary labels from cut-layer gradients. They introduce a privacy loss metric termed leak AUC, which measures an adversary's classification performance across all decision thresholds, where a value of 1.0 indicates total label leakage and 0.5 denotes random guessing. The authors demonstrate two realistic attack methods based on gradient length and direction. To counter these threats, they formulate a defense named Marvell, which mathematically optimizes class-specific Gaussian noise perturbations to minimize worst-case label leakage under strict optimization power constraints. The authors evaluate these attacks and defenses across three large-scale benchmark datasets: online advertising datasets Criteo and Avazu, and the SIIM-ISIC skin lesion image dataset.

The findings demonstrate that split learning without active defenses suffers from severe privacy leakage. In unperturbed training across all datasets, both the gradient norm and gradient direction scoring attacks consistently achieve leak AUC values near 1.0, enabling the non-label party to fully reconstruct private ground-truth labels at both the cut layer and internal network layers. Standard isotropic Gaussian noise fails to defend against directional attacks, leaving leak AUC values above 0.9 on the image dataset even when high noise is added. In contrast, Marvell reduces worst-case leak AUC close to the baseline level of 0.5 across both cut and earlier network layers while preserving predictive accuracy. An alternative heuristic defense, max_norm, also effectively mitigates the identified attacks but lacks the mathematical flexibility to tune privacy-utility tradeoffs.

These results demonstrate that standard split learning provides an illusion of label privacy. Gradient exchanges create substantial compliance, security, and competitive risks for institutions handling proprietary outcomes. Marvell demonstrates that mathematically structured noise—aligning perturbations with the difference between positive and negative class gradient distributions—effectively eliminates label reconstruction risks while maintaining viable model utility and generalization performance on real-world tasks.

Organizations deploying split learning in production should not rely on raw gradient exchanges and should implement structured perturbation defenses. Marvell is recommended when organizations require explicit, tunable control over the balance between privacy protection and predictive performance. For simpler implementations where hyperparameter tuning is impractical, the max_norm heuristic offers an effective out-of-the-box alternative against standard geometric attacks. Future development should evaluate defenses in multi-class classification, multi-party federated architectures, and against potential multi-step attacks where adversaries track historical gradients over multiple update iterations.

The conclusions are supported by theoretical bounds and extensive empirical validations across tabular and image domains. However, decision-makers should recognize that the optimization framework assumes class-conditional gradients approximate Gaussian distributions and focuses on binary classification. Confidence in the defense is high for standard single-iteration attacks, but additional testing is warranted before deploying in non-binary or multi-party collaborative environments.

  • Paper: Deep Leakage from Gradients, Ligeng Zhu et al. (2019). This seminal paper demonstrates how private training inputs and labels can be mathematically inverted and reconstructed from shared gradients in collaborative learning architectures.
  • Paper: Inverting Gradients - How easy is it to break privacy in federated learning?, Jonas Geiping et al. (2020). This work establishes theoretical bounds and numerical methods showing that deep network layer inputs can be reconstructed strictly from parameter gradient updates.
  • Paper: Exploiting Unintended Feature Leakage in Collaborative Learning, Luca Melis et al. (2018). This study analyzes passive and active feature and property leakage stemming from intermediate gradient exchanges in collaborative multi-party learning.
  • Paper: Deep Learning with Differential Privacy, Martín Abadi et al. (2016). This foundational work introduces gradient perturbation mechanisms and privacy budgeting via differentially private stochastic gradient descent.
  • Paper: Federated Machine Learning, Qiang Yang et al. (2019). This paper establishes the taxonomy and architecture of vertical and split federated learning across organizations with partitioned features and labels.
  • Paper: Differentially Private Empirical Risk Minimization, Kamalika Chaudhuri et al. (2009). This study formalizes objective and output perturbation strategies for differential privacy in risk minimization, grounding noise optimization under utility constraints.
Cover for Label Leakage and Protection in Two-party Split Learning

Abstract

Two-party split learning is a popular technique for learning a model across feature-partitioned data. In this work, we explore whether it is possible for one party to steal the private label information from the other party during split training, and whether there are methods that can protect against such attacks. Specifically, we first formulate a realistic threat model and propose a privacy loss metric to quantify label leakage in split learning. We then show that there exist two simple yet effective methods within the threat model that can allow one party to accurately recover private ground-truth labels owned by the other party. To combat these attacks, we propose several random perturbation techniques, including Marvell\texttt{Marvell}, an approach that strategically finds the structure of the noise perturbation by minimizing the amount of label leakage (measured through our quantification metric) of a worst-case adversary. We empirically demonstrate the effectiveness of our protection techniques against the identified attacks, and show that Marvell\texttt{Marvell} in particular has improved privacy-utility tradeoffs relative to baseline approaches.

Table of Contents

  • 1 Introduction
  • 2 Related Work
  • 3 Label Leakage in Split Learning
  • 3.1 Two-party Split Learning in Binary Classification
  • 3.2 Threat Model and Privacy Quantification
  • 3.3 Practical Attack Methods
  • 4 Label Leakage Protection Methods
  • 4.1 A Heuristic Protection Approach
  • 4.2 Optimized Perturbation Method: Marvell
  • 5 Experiments
  • 5.1 Label Leakage and Marvell’s Strong and Flexible Protection
  • 5.2 Privacy-Utility Trade-off Comparison
  • 6 Conclusion
  • References
  • A Appendix
  • A.1 Expressing AUC​(r)\textrm{AUC}(r) as an integral
  • A.2 Toy example of positive example prediction lacking confidence
  • A.3 Proof of Theorem
  • A.4 Proof and Interpretation of Theorem
  • A.5 Marvell algorithm description
  • A.6 Data Setup and Experimental Details
  • A.6.1 Dataset preprocessing
  • A.6.2 Model architecture details
  • A.6.3 Model training details
  • A.7 Complete Experimental Results
  • A.7.1 Leak AUC progression for Avazu and Criteo
  • A.7.2 Complete Privacy-Utility tradeoffs

Knowls

  1. Knowl 1 — Upper Bound on Worst-Case Label Leakage AUC via Symmetrized KL Divergence

    theoretical result

    Let P~(1)\tilde{P}^{(1)} and P~(0)\tilde{P}^{(0)} denote the perturbed cut-layer gradient distributions for the positive (y=1y=1) and negative (y=0y=0) classes respectively, which are absolutely continuous with respect to each other.

    For any adversary scoring function r:Rd→Rr: \mathbb{R}^d \to \mathbb{R}, let AUC(r)\text{AUC}(r) denote the area under the ROC curve measuring the adversary's ability to classify the ground-truth label yy from the perturbed gradient g~\tilde{g}. If the symmetrized Kullback-Leibler (KL) divergence between the perturbed distributions satisfies

    KL(P~(1)∥P~(0))+KL(P~(0)∥P~(1))≤ϵ\text{KL}(\tilde{P}^{(1)} \parallel \tilde{P}^{(0)}) + \text{KL}(\tilde{P}^{(0)} \parallel \tilde{P}^{(1)}) \le \epsilon

    for some 0≤ϵ<40 \le \epsilon < 4, then the maximum leak AUC across all measurable scoring functions is bounded by:

    max⁡rAUC(r)≤12+ϵ2−ϵ8\max_r \text{AUC}(r) \le \frac{1}{2} + \frac{\sqrt{\epsilon}}{2} - \frac{\epsilon}{8}

    Because 12+ϵ2−ϵ8\frac{1}{2} + \frac{\sqrt{\epsilon}}{2} - \frac{\epsilon}{8} decreases monotonically as ϵ→0\epsilon \to 0, minimizing the symmetrized KL divergence directly minimizes the worst-case adversary's label-recovery capability.

  2. Knowl 2 — Optimal Perturbation Noise Covariance Structure in Marvell

    theoretical result

    Assume unperturbed cut-layer gradients for the positive and negative classes follow isotropic Gaussian distributions g(1)∼N(gˉ(1),vId)g^{(1)} \sim \mathcal{N}(\bar{g}^{(1)}, v I_d) and g(0)∼N(gˉ(0),uId)g^{(0)} \sim \mathcal{N}(\bar{g}^{(0)}, u I_d), where gˉ(1),gˉ(0)∈Rd\bar{g}^{(1)}, \bar{g}^{(0)} \in \mathbb{R}^d are class mean gradient vectors, u,v>0u, v > 0 are scalar variances, and IdI_d is the d×dd \times d identity matrix. Let Δg:=gˉ(1)−gˉ(0)\Delta g := \bar{g}^{(1)} - \bar{g}^{(0)} be the difference between class means.

    Consider additive zero-mean Gaussian perturbations η(1)∼N(0,Σ1)\eta^{(1)} \sim \mathcal{N}(0, \Sigma_1) and η(0)∼N(0,Σ0)\eta^{(0)} \sim \mathcal{N}(0, \Sigma_0) with commuting positive semidefinite covariance matrices Σ1Σ0=Σ0Σ1\Sigma_1 \Sigma_0 = \Sigma_0 \Sigma_1, subject to the total noise power constraint

    p⋅tr(Σ1)+(1−p)⋅tr(Σ0)≤Pp \cdot \text{tr}(\Sigma_1) + (1-p) \cdot \text{tr}(\Sigma_0) \le P

    where p∈(0,1)p \in (0, 1) is the positive class proportion and P>0P > 0 is the noise power budget.

    The optimal covariance matrices Σ1∗,Σ0∗\Sigma_1^*, \Sigma_0^* minimizing the symmetrized KL divergence KL(N(gˉ(1),vId+Σ1)∥N(gˉ(0),uId+Σ0))+KL(N(gˉ(0),uId+Σ0)∥N(gˉ(1),vId+Σ1))\text{KL}(\mathcal{N}(\bar{g}^{(1)}, v I_d + \Sigma_1) \parallel \mathcal{N}(\bar{g}^{(0)}, u I_d + \Sigma_0)) + \text{KL}(\mathcal{N}(\bar{g}^{(0)}, u I_d + \Sigma_0) \parallel \mathcal{N}(\bar{g}^{(1)}, v I_d + \Sigma_1)) are given by:

    Σ1∗=λ1(1)∗−λ2(1)∗∥Δg∥22(Δg)(Δg)⊤+λ2(1)∗Id\Sigma_1^* = \frac{\lambda_1^{(1)*} - \lambda_2^{(1)*}}{\|\Delta g\|_2^2} (\Delta g)(\Delta g)^\top + \lambda_2^{(1)*} I_d

    Σ0∗=λ1(0)∗−λ2(0)∗∥Δg∥22(Δg)(Δg)⊤+λ2(0)∗Id\Sigma_0^* = \frac{\lambda_1^{(0)*} - \lambda_2^{(0)*}}{\|\Delta g\|_2^2} (\Delta g)(\Delta g)^\top + \lambda_2^{(0)*} I_d

    where (λ1(0)∗,λ2(0)∗,λ1(1)∗,λ2(1)∗)(\lambda_1^{(0)*}, \lambda_2^{(0)*}, \lambda_1^{(1)*}, \lambda_2^{(1)*}) is the solution to the 4-variable convex optimization problem:

    min⁡λ1(0),λ1(1),λ2(0),λ2(1)(d−1)λ2(0)+uλ2(1)+v+(d−1)λ2(1)+vλ2(0)+u+λ1(0)+u+∥Δg∥22λ1(1)+v+λ1(1)+v+∥Δg∥22λ1(0)+u\min_{\lambda_1^{(0)}, \lambda_1^{(1)}, \lambda_2^{(0)}, \lambda_2^{(1)}} (d-1)\frac{\lambda_2^{(0)} + u}{\lambda_2^{(1)} + v} + (d-1)\frac{\lambda_2^{(1)} + v}{\lambda_2^{(0)} + u} + \frac{\lambda_1^{(0)} + u + \|\Delta g\|_2^2}{\lambda_1^{(1)} + v} + \frac{\lambda_1^{(1)} + v + \|\Delta g\|_2^2}{\lambda_1^{(0)} + u}

    subject to

    pλ1(1)+p(d−1)λ2(1)+(1−p)λ1(0)+(1−p)(d−1)λ2(0)≤Pp \lambda_1^{(1)} + p(d-1)\lambda_2^{(1)} + (1-p)\lambda_1^{(0)} + (1-p)(d-1)\lambda_2^{(0)} \le P

    −λ1(1)≤0,−λ1(0)≤0,−λ2(1)≤0,−λ2(0)≤0-\lambda_1^{(1)} \le 0, \quad -\lambda_1^{(0)} \le 0, \quad -\lambda_2^{(1)} \le 0, \quad -\lambda_2^{(0)} \le 0

    λ2(1)−λ1(1)≤0,λ2(0)−λ1(0)≤0\lambda_2^{(1)} - \lambda_1^{(1)} \le 0, \quad \lambda_2^{(0)} - \lambda_1^{(0)} \le 0

    At the optimal solution, λ2(1)∗=0\lambda_2^{(1)*} = 0 if u<vu < v and λ2(0)∗=0\lambda_2^{(0)*} = 0 if u≥vu \ge v, reducing the active variables to three.

  3. Knowl 3 — Marvell Algorithm for Label Leakage Protection

    algorithm

    Marvell (optiMized perturbAtion to pReVEnt Label Leakage) is executed by the label party at each training step of two-party split learning. It dynamically estimates batch statistics, solves a 3-variable convex subproblem to find optimal perturbation covariance matrices Σ1∗\Sigma_1^* and Σ0∗\Sigma_0^*, and perturbs positive and negative cut-layer gradients prior to sending them back to the non-label party.

    Input: Batch gradients g∈RB×dg \in \mathbb{R}^{B \times d}, labels y∈{0,1}By \in \{0, 1\}^B, privacy scale hyperparameter s>0s > 0
    Output: Perturbed batch gradients g~∈RB×d\tilde{g} \in \mathbb{R}^{B \times d}
    p←1B∑j=1By[j]p \leftarrow \frac{1}{B} \sum_{j=1}^B y[j]
    gˉ(1)←1∑j=1By[j]∑j:y[j]=1g[j]\bar{g}^{(1)} \leftarrow \frac{1}{\sum_{j=1}^B y[j]} \sum_{j: y[j]=1} g[j]
    gˉ(0)←1∑j=1B(1−y[j])∑j:y[j]=0g[j]\bar{g}^{(0)} \leftarrow \frac{1}{\sum_{j=1}^B (1-y[j])} \sum_{j: y[j]=0} g[j]
    v←1d∑j=1By[j]∑j:y[j]=1∥g[j]−gˉ(1)∥22v \leftarrow \frac{1}{d \sum_{j=1}^B y[j]} \sum_{j: y[j]=1} \|g[j] - \bar{g}^{(1)}\|_2^2
    u←1d∑j=1B(1−y[j])∑j:y[j]=0∥g[j]−gˉ(0)∥22u \leftarrow \frac{1}{d \sum_{j=1}^B (1-y[j])} \sum_{j: y[j]=0} \|g[j] - \bar{g}^{(0)}\|_2^2
    Δg←gˉ(1)−gˉ(0)\Delta g \leftarrow \bar{g}^{(1)} - \bar{g}^{(0)}
    P←s⋅∥Δg∥22P \leftarrow s \cdot \|\Delta g\|_2^2
    if u<vu < v then
        λ2(1)←0\lambda_2^{(1)} \leftarrow 0
        Initialize λ1(1),λ1(0),λ2(0)\lambda_1^{(1)}, \lambda_1^{(0)}, \lambda_2^{(0)} in the feasible region
    else
        λ2(0)←0\lambda_2^{(0)} \leftarrow 0
        Initialize λ1(1),λ2(1),λ1(0)\lambda_1^{(1)}, \lambda_2^{(1)}, \lambda_1^{(0)} in the feasible region
    end if
    while not converged do
        Fix one of the three active optimization variables
        Update the other two variables along the hyperplane constraint via 1D line-search minimization of the convex objective
    end while
    Σ1∗←λ1(1)−λ2(1)∥Δg∥22(Δg)(Δg)⊤+λ2(1)Id\Sigma_1^* \leftarrow \frac{\lambda_1^{(1)} - \lambda_2^{(1)}}{\|\Delta g\|_2^2} (\Delta g)(\Delta g)^\top + \lambda_2^{(1)} I_d
    Σ0∗←λ1(0)−λ2(0)∥Δg∥22(Δg)(Δg)⊤+λ2(0)Id\Sigma_0^* \leftarrow \frac{\lambda_1^{(0)} - \lambda_2^{(0)}}{\|\Delta g\|_2^2} (\Delta g)(\Delta g)^\top + \lambda_2^{(0)} I_d
    g~←0B×d\tilde{g} \leftarrow 0_{B \times d}
    for j=1j = 1 to BB do
        if y[j]=1y[j] = 1 then
            Sample η(1)∼N(0,Σ1∗)\eta^{(1)} \sim \mathcal{N}(0, \Sigma_1^*)
            g~[j]←g[j]+η(1)\tilde{g}[j] \leftarrow g[j] + \eta^{(1)}
        else
            Sample η(0)∼N(0,Σ0∗)\eta^{(0)} \sim \mathcal{N}(0, \Sigma_0^*)
            g~[j]←g[j]+η(0)\tilde{g}[j] \leftarrow g[j] + \eta^{(0)}
        end if
    end for
    return g~\tilde{g}
  4. Knowl 4 — Leak AUC Privacy Quantification Metric

    definition

    In two-party split learning for binary classification with private labels y∈{0,1}y \in \{0, 1\}, privacy leakage to an honest-but-curious non-label party is quantified using the Leak AUC metric. Let P(1)P^{(1)} and P(0)P^{(0)} denote the cut-layer gradient distributions for the positive and negative class, respectively.

    The adversary employs a classifier represented by a real-valued scoring function r:Rd→Rr: \mathbb{R}^d \to \mathbb{R} and threshold t∈Rt \in \mathbb{R}, predicting y^=1\hat{y} = 1 when r(g)>tr(g) > t and y^=0\hat{y} = 0 otherwise. The false positive rate and true positive rate at threshold tt are:

    FPRr(t):=P(0)({g∈Rd:r(g)>t})\text{FPR}_r(t) := P^{(0)}(\{g \in \mathbb{R}^d : r(g) > t\})

    TPRr(t):=P(1)({g∈Rd:r(g)>t})\text{TPR}_r(t) := P^{(1)}(\{g \in \mathbb{R}^d : r(g) > t\})

    The Leak AUC of scoring function rr is defined via the Riemann-Stieltjes integral:

    AUC(r)=∫t=∞t=−∞TPRr(t) dFPRr(t)∈[0,1]\text{AUC}(r) = \int_{t=\infty}^{t=-\infty} \text{TPR}_r(t) \, d\text{FPR}_r(t) \in [0, 1]

    A Leak AUC of 1.01.0 indicates complete label recovery, whereas AUC(r)≈0.5\text{AUC}(r) \approx 0.5 denotes non-informative random guessing. Differential privacy is not directly applicable because communicated cut-layer gradients are example-specific matrices in RB×d\mathbb{R}^{B \times d} whose rows cannot be aggregated or permuted without destroying non-label parameter updates.

  5. Knowl 5 — Norm-Based and Direction-Based Label Leakage Attacks in Two-Party Split Learning

    model/method

    In two-party split binary classification with loss L=log⁡(1+exp⁡(−ℓ))+(1−y)ℓL = \log(1 + \exp(-\ell)) + (1-y)\ell, the cut-layer gradient sent from the label party to the non-label party is g=(p~1−y)∇zh(z)∣z=f(X)∈Rdg = (\tilde{p}_1 - y) \nabla_z h(z)|_{z=f(X)} \in \mathbb{R}^d, where p~1=1/(1+exp⁡(−ℓ))\tilde{p}_1 = 1/(1 + \exp(-\ell)) is the model's positive class probability and hh is the label party's logit function.

    The non-label party can exploit two structural properties of gg:

    1. Norm-based scoring function rn(g)=∥g∥2r_n(g) = \|g\|_2: Because neural networks typically have lower prediction confidence for positive instances (1−p~11 - \tilde{p}_1) than negative instances (p~1\tilde{p}_1), the confidence gap ∣p~1−y∣|\tilde{p}_1 - y| is larger for y=1y=1 than for y=0y=0. Since ∥∇zh(z)∥2\|\nabla_z h(z)\|_2 is independent of yy, ∥g∥2=∣p~1−y∣⋅∥∇zh(z)∥2\|g\|_2 = |\tilde{p}_1 - y| \cdot \|\nabla_z h(z)\|_2 is systematically larger for positive examples.

    2. Direction-based scoring function rd(g)=cos⁡(g,g+)r_d(g) = \cos(g, g^+): For two examples aa and bb, cos⁡(ga,gb)=sgn(p~1,a−ya)sgn(p~1,b−yb)cos⁡(∇zh(za),∇zh(zb))\cos(g_a, g_b) = \text{sgn}(\tilde{p}_{1,a} - y_a) \text{sgn}(\tilde{p}_{1,b} - y_b) \cos(\nabla_z h(z_a), \nabla_z h(z_b)). When monotonic activations (such as ReLU) are used, gradients of hh lie in the first hyperorthant so cos⁡(∇zh(za),∇zh(zb))>0\cos(\nabla_z h(z_a), \nabla_z h(z_b)) > 0. Thus, same-class pairs always produce positive cosine similarity, and opposite-class pairs produce negative cosine similarity. Using a single clean positive gradient g+g^+ (or majority counting under class imbalance), rd(g)=cos⁡(g,g+)r_d(g) = \cos(g, g^+) separates positive from negative examples.

  6. Knowl 6 — Max-Norm Heuristic Perturbation Defense

    model/method

    The max-norm heuristic (max_norm\text{max\_norm}) is a parameter-free perturbation method designed to neutralize norm- and direction-based gradient attacks in two-party split learning while keeping gradient estimates unbiased (E[g~∣g]=g\mathbb{E}[\tilde{g} \mid g] = g).

    For a mini-batch of cut-layer gradients {gj}j=1B⊂Rd\{g_j\}_{j=1}^B \subset \mathbb{R}^d, the label party determines the maximum squared 2-norm:

    ∥gmax⁡∥22=max⁡j∈{1,…,B}∥gj∥22\|g_{\max}\|_2^2 = \max_{j \in \{1, \dots, B\}} \|g_j\|_2^2

    For each gradient gjg_j, zero-mean Gaussian noise ηj\eta_j is added along the 1-dimensional subspace defined by gjg_j with rank-1 covariance matrix:

    Cov[ηj]=σj2gjgj⊤whereσj=∥gmax⁡∥22∥gj∥22−1\text{Cov}[\eta_j] = \sigma_j^2 g_j g_j^\top \quad \text{where} \quad \sigma_j = \sqrt{\frac{\|g_{\max}\|_2^2}{\|g_j\|_2^2} - 1}

    This ensures that every perturbed gradient g~j=gj+ηj\tilde{g}_j = g_j + \eta_j has expected squared 2-norm equal to the batch maximum: E[∥gj+ηj∥22]=∥gmax⁡∥22\mathbb{E}[\|g_j + \eta_j\|_2^2] = \|g_{\max}\|_2^2.

  7. Knowl 7 — Two-Party Split Learning Protocol for Binary Classification

    model/method

    Two-party split learning for binary classification distributes a composition model h∘fh \circ f between a non-label party and a label party over domain X×{0,1}\mathcal{X} \times \{0, 1\}:

    1. Forward Pass: The non-label party holds raw features X∈XX \in \mathcal{X} and representation function f:X→Rdf: \mathcal{X} \to \mathbb{R}^d. It computes cut-layer activation f(X)∈Rdf(X) \in \mathbb{R}^d and sends it to the label party. The label party holds ground-truth labels y∈{0,1}y \in \{0, 1\} and logit function h:Rd→Rh: \mathbb{R}^d \to \mathbb{R}. It computes logit ℓ=h(f(X))\ell = h(f(X)), positive class probability p~1=1/(1+exp⁡(−ℓ))\tilde{p}_1 = 1/(1 + \exp(-\ell)), and cross-entropy loss L=log⁡(1+exp⁡(−ℓ))+(1−y)ℓL = \log(1 + \exp(-\ell)) + (1-y)\ell.

    2. Backward Pass: The label party computes the loss gradient with respect to the cut-layer activation:

    g:=∇f(X)L=(p~1−y)∇zh(z)∣z=f(X)∈Rdg := \nabla_{f(X)} L = (\tilde{p}_1 - y) \nabla_z h(z)\Big|_{z=f(X)} \in \mathbb{R}^d

    The label party updates its parameters in hh using ∇L\nabla L, and sends gg back to the non-label party. The non-label party continues backpropagation from gg to update parameters in ff.

  8. Knowl 8 — Empirical Privacy-Utility Trade-Offs of Marvell vs. Baselines

    empirical result

    Experiments evaluated Marvell, isotropic Gaussian noise (iso\text{iso} with η∼N(0,(t/d)∥gmax⁡∥22Id)\eta \sim \mathcal{N}(0, (t/d)\|g_{\max}\|_2^2 I_d)), max_norm\text{max\_norm}, and unperturbed training (no_noise\text{no\_noise}) on Criteo and Avazu (click-through rate prediction using Wide&Deep models) and SIIM-ISIC (skin lesion classification using a 6-layer CNN, subsampled to a 10% positive ratio). Privacy is evaluated using the 95th percentile of batch-computed norm and cosine Leak AUC at both the cut layer and the first layer; utility is evaluated via test loss, test AUC, and train loss across 20+ runs per method.

    Key empirical results include:

    1. High baseline leakage: Without perturbation (no_noise\text{no\_noise}), norm leak AUC exceeds 0.9 and cosine leak AUC equals 1.0 across iterations at both the cut layer and first layer, demonstrating severe label leakage.

    2. Marvell vs. Isotropic Gaussian: Marvell achieves strictly superior privacy-utility curves over iso\text{iso}. On ISIC, even with large isotropic noise (t>20t > 20), iso\text{iso}'s cosine leak AUC remains >0.9> 0.9 at the cut layer, while Marvell reduces cosine leak AUC to ≈0.6\approx 0.6 with test AUC ≈0.83\approx 0.83 and test loss ≈0.38\approx 0.38.

    3. Flexible protection: Varying Marvell's scale parameter ss from 0.1 to 4.0 continuously reduces both norm and cosine leak AUC from ≈1.0\approx 1.0 down to ≈0.5\approx 0.5 (random guess) at both the cut layer and the non-label party's first layer.

    4. Max-norm heuristic: The parameter-free max_norm\text{max\_norm} matches or slightly outperforms Marvell at a single fixed privacy-utility operating point, but lacks a tuning hyperparameter to adjust the trade-off.

Coverage note — No substantial contributed material was omitted; all core theoretical bounds, algorithmic specifications, attack formulations, heuristic defenses, and empirical results are included.

References

  1. 1.Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. Communication-efficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics, pages 1273–1282. PMLR, 2017.
  2. 2.Qiang Yang, Yang Liu, Tianjian Chen, and Yongxin Tong. Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology (TIST), 10(2):1–19, 2019.
  3. 3.Otkrist Gupta and Ramesh Raskar. Distributed learning of deep neural network over multiple agents. Journal of Network and Computer Applications, 116:1–8, 2018.
  4. 4.Praneeth Vepakomma, Otkrist Gupta, Tristan Swedish, and Ramesh Raskar. Split learning for health: Distributed deep learning without sharing raw patient data. arXiv preprint arXiv:1812.00564, 2018.
  5. 5.Vladimir Kolesnikov, Ranjit Kumaresan, Mike Rosulek, and Ni Trieu. Efficient batched oblivious prf with applications to private set intersection. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS ’16, page 818–829, 2016.
  6. 6.Benny Pinkas, Thomas Schneider, and Michael Zohner. Scalable private set intersection based on ot extension. ACM Transactions on Privacy and Security (TOPS), 21(2):1–35, 2018.
  7. 7.Ligeng Zhu, Zhijian Liu, and Song Han. Deep leakage from gradients. In Advances in Neural Information Processing Systems, pages 14774–14784, 2019.
  8. 8.Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. idlg: Improved deep leakage from gradients. arXiv preprint arXiv:2001.02610, 2020.
  9. 9.Praneeth Vepakomma, Otkrist Gupta, Abhimanyu Dubey, and Ramesh Raskar. Reducing leakage in distributed deep learning for sensitive health data. arXiv preprint arXiv:1812.00564, 2019.
  10. 10.Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. Practical secure aggregation for privacy-preserving machine learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 1175–1191, 2017.
  11. 11.Pramod Subramanyan, Rohit Sinha, Ilia Lebedev, Srinivas Devadas, and Sanjit A Seshia. A formal foundation for secure remote execution of enclaves. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 2435–2450, 2017.
  12. 12.Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 308–318, 2016.
  13. 13.H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. Learning differentially private recurrent language models. In International Conference on Learning Representations, 2018. URL https://openreview.net/forum?id=BJ0hF1Z0b.
  14. 14.Úlfar Erlingsson, Vitaly Feldman, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Abhradeep Thakurta. Amplification by shuffling: From local to central differential privacy via anonymity. In Proceedings of the Thirtieth Annual ACM-SIAM Symposium on Discrete Algorithms, pages 2468–2479. SIAM, 2019.
  15. 15.Albert Cheu, Adam Smith, Jonathan Ullman, David Zeber, and Maxim Zhilyaev. Distributed differential privacy via shuffling. In Annual International Conference on the Theory and Applications of Cryptographic Techniques, pages 375–403. Springer, 2019.
  16. 16.Cynthia Dwork. Differential privacy. In Michele Bugliesi, Bart Preneel, Vladimiro Sassone, and Ingo Wegener, editors, Automata, Languages and Programming, pages 1–12, Berlin, Heidelberg, 2006. Springer Berlin Heidelberg. ISBN 978-3-540-35908-1.
  17. 17.Cynthia Dwork, Aaron Roth, et al. The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3-4):211–407, 2014.
  18. 18.Kamalika Chaudhuri and Daniel Hsu. Sample complexity bounds for differentially private learning. In Proceedings of the 24th Annual Conference on Learning Theory, pages 155–186. JMLR Workshop and Conference Proceedings, 2011.
  19. 19.Badih Ghazi, Noah Golowich, Ravi Kumar, Pasin Manurangsi, and Chiyuan Zhang. On deep learning with label differential privacy. arXiv preprint arXiv:2102.06062, 2021.
  20. 20.Criteo. Criteo display advertising challenge, 2014. URL https://www.kaggle.com/c/criteo-display-ad-challenge/data.
  21. 21.Avazu. Avazu click-through rate prediction, 2015. URL https://www.kaggle.com/c/avazu-ctr-prediction/data.
  22. 22.ISIC. Siim-isic melanoma classification, 2020. URL https://www.kaggle.com/c/siim-isic-melanoma-classification/data.
  23. 23.Heng-Tze Cheng, Levent Koc, Jeremiah Harmsen, Tal Shaked, Tushar Chandra, Hrishi Aradhye, Glen Anderson, Greg Corrado, Wei Chai, Mustafa Ispir, et al. Wide & deep learning for recommender systems. In Proceedings of the 1st workshop on deep learning for recommender systems, pages 7–10, 2016.

Citation

MLA
Li, O., et al. “Label Leakage and Protection in Two-party Split Learning”. arXiv, 2021, http://arxiv.org/abs/2102.08504v3.
APA
Li, O., Sun, J., Yang, X., Gao, W., Zhang, H., Xie, J., Smith, V., & Wang, C. (2021). Label Leakage and Protection in Two-party Split Learning. arXiv. http://arxiv.org/abs/2102.08504v3
Chicago
Li, O., J. Sun, X. Yang, et al. 2021. “Label Leakage and Protection in Two-party Split Learning”. arXiv. http://arxiv.org/abs/2102.08504v3.
Harvard
Li, O. et al. (2021) “Label Leakage and Protection in Two-party Split Learning”, arXiv [Preprint]. Available at: http://arxiv.org/abs/2102.08504v3.
Vancouver
1. Li O, Sun J, Yang X, Gao W, Zhang H, Xie J, Smith V, Wang C (2021) Label Leakage and Protection in Two-party Split Learning. arXiv

BibTeX

@article{li2021label,
  title = {Label Leakage and Protection in Two-party Split Learning},
  author = {Li, Oscar and Sun, Jiankai and Yang, Xin and Gao, Weihao and Zhang, Hongyi and Xie, Junyuan and Smith, Virginia and Wang, Chong},
  year = {2021},
  journal = {arXiv},
  url = {http://arxiv.org/abs/2102.08504v3},
  eprint = {2102.08504}
}
Metadata:arXiv

Source Code

This paper has an official code repository available. Click below to access the source code.

View Repository

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: Authors