arrow
返回

Gradient Inversion of Text-Modal Data in Distributed Learning

delete2025-01-01
delete0
PRE
AI
Z
Zipeng Ye
W
Wenjian Luo *
Q
Qi Zhou
Y
Yubo Tang
Z
Zhenqian Zhu
Yuhui Shi 封面图
Yuhui Shi (Yuhui Shi)
Y
Yan Jia
DOI:10.1109/TIFS.2024.3522792delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Gradient inversion attacks (GIAs) pose significant challenges to the privacy-preserving paradigm of distributed learning. These attacks employ carefully designed strategies to reconstruct victim's private training data from their shared gradients. However, existing work mainly focuses on attacks and defenses for image-modal data, while the study for text-modal data remains scarce. Furthermore, the performance of the limited attack researches on text-modal data is also unsatisfactory, which can be partially attributed to the finer granularity of text data compared to image. To bridge the existing research gap, we propose a high-fidelity attack method tailored for Transformer-based language models (LMs). In our method, we initially reconstruct the label space of the victim's training data by leveraging the characteristics of the Transformer architecture. After that, we propose a shallow-to-deep paradigm to facilitate gradient matching, which can significantly improve the attack performance. Furthermore, we develop a weighted surrogate loss that resolves the consistent deviation issue present in current attack researches. A substantial number of experiments on Transformer-based LMs (e.g., Bert and GPT) demonstrate that our attack is competitive and significantly outperforms existing methods. In the final part of this paper, we investigate the influence of the inherent position embedding module within the Transformer architecture on attack performance, and based on the analysis results, we propose a countermeasure to alleviate part of the privacy leakage issue in distributed learning.
Keyword:
Image reconstruction
Data models
Transformers
Distance learning
Data privacy
Computer aided instruction
Training data
Distributed databases
Training
Mathematical models
Distributed learning
privacy preserving
language model
Transformer
gradient inversion attack

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

H
harbin institute of technology
学者数:
8.0W
论文数: 6.6W
被引数: 66
引用论文

引用论文

Parkinson's disease: Nigral receptor changes support peptidergic role in nigrostriatal modulation
err2004-10-08
err0
PREAI
errGeorge R. Uhl; Gail O. Hackney; Mary Torchia; Victoria Stranov; Wallace W. Tourtellotte; Peter J. Whitehouse; Vinh Tran; Steven Strittmatter
err分享
err收藏
err分享
err收藏
err分享
err收藏
err分享
err收藏
err分享
err收藏
Distributed Learning in Wireless Networks: Recent Progress and Future Challenges无线网络中的分布式学习: 最新进展和未来挑战
err2021-12-01
err271
errOAAI
errChen, Mingzhe; Gunduz, Deniz; Huang, Kaibin; Saad, Walid; Bennis, Mehdi; Feljan, Aneta Vulgarakis; Poor, H. Vincent
err分享
err收藏
学者 查看更多内容