返回
EncGradInversion: Image Encoding and Gradient-Inversion-Based Batch Attack in Federated Learning
DOI:10.1109/JIOT.2024.3483850.png)
摘要
En 中文
The gradient attack problem has recently been studied to increase the awareness of people on privacy risks in federated learning. However, this attack is constrained under specific conditions, such as small image batch sizes and low image resolutions. To address this challenge, we introduce a new three-phase image recovery architecture called EncGradInversion, which harnesses the power of image encoding and the shared gradient inversion. In the first phase, we attempt to extract the representation for all of the images using the gradient at the final layer. Then, in the second phase, the extracted encoding of a specific image is leveraged for reconstructing the image by matching the representation of dummy and approximated images. This allows a parallel algorithm to accelerate the image recovery. In the final phase, the reconstructed images are fine tuned using the shared gradient of the whole network. In the second and third phases, we formulate an optimization problem to minimize the discrepancy between the shared and reconstructed gradients, while preserving the smoothness and natural appearance of the reconstructed images. Evaluated on various datasets and deep learning models, EncGradInversion shows its superiority to recover the original training images with resolutions as high as 1024x1024 and with the batch size of 512. Furthermore, the proposed architecture outperforms existing counterparts with a factor of up to 9.8 and 6.04, in terms of structural similarity performance and attack time.
Keyword:
Image reconstruction
Training
Image coding
Image resolution
Optimization
Internet of Things
Image representation
Loss measurement
Federated learning
Linear programming
Federated learning (FL)
gradient inversion
gradient leakage attack
image recovery
期刊
IF:
8.9
论文数:
1.4W
被引数:
7.8W
机构
引用论文
Intravascular oxygen sensors with novel applications for bedside respiratory monitoring
Anaesthesia
IF0
Using Highly Compressed Gradients in Federated Learning for Data Reconstruction Attacks在联合学习中使用高度压缩的梯度进行数据重建攻击
Federated Learning for Medical Image Analysis with Deep Neural Networks基于深度神经网络的医学图像分析联邦学习
DIAGNOSTICS
IF3.3

