arrow
Return

Do Gradient Inversion Attacks Make Federated Learning Unsafe?

delete2023-07-01
delete19
delete
OA
AI
A
Ali Hatamizadeh
P
Pavlo Molchanov
A
Andriy Myronenko
W
Wenqi Li
P
Prerna Dogra
A
Andrew Feng
M
Mona G. Flores
J
Jan Kautz
D
Daguang Xu
H
Holger R. Roth *
DOI:10.1109/TMI.2023.3239391delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Federated learning (FL) allows the collaborative training of AI models without needing to share raw data. This capability makes it especially interesting for healthcare applications where patient and data privacy is of utmost concern. However, recent works on the inversion of deep neural networks from model gradients raised concerns about the security of FL in preventing the leakage of training data. In this work, we show that these attacks presented in the literature are impractical in FL use-cases where the clients' training involves updating the Batch Normalization (BN) statistics and provide a new baseline attack that works for such scenarios. Furthermore, we present new ways to measure and visualize potential data leakage in FL. Our work is a step towards establishing reproducible methods of measuring data leakage in FL and could help determine the optimal tradeoffs between privacy-preserving techniques, such as differential privacy, and model accuracy based on quantifiable metrics.
Keywords:
Deep Learning
gradient inversion
federated learning
patient privacy
security

Journal

IEEE Transactions on Medical Imaging cover
IEEE Transactions on Medical Imaging
IF:
9.8
Papers:
6.2K
Citations:
3.7W

Organization

N
nvidia corporation
Scholars:
764
Papers: 437
Citations: 1