arrow
Return

A gradient inversion attack defense method based on data augmentation

delete2025-09-09
delete0
PRE
AI
Y
Yingge Li
X
X. H. Wu
陈渝文 cover
陈渝文 (Yuwen Chen) *
H
Haiyang Yu
Z
Zhen Yang
DOI:10.1007/s10489-025-06533-ydelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The gradient inversion attack presents a significant threat to the data privacy in federated learning, enabling malicious adversaries to reconstruct private training data from gradients. Among the various protection strategies, data augmentation-based approaches have emerged as particularly promising. These methods can be seamlessly incorporated into existing federated learning frameworks, offering both efficiency and minimal impact on model accuracy. In this paper, we propose a novel data protection technique that leverages data augmentation methods, specifically CutMix and SaliencyMix. These techniques work by mixing images, which allows for more efficient utilization of training pixels. This, in turn, aids the model in learning more robust and meaningful feature representations, thereby enhancing both the model performance and its resilience to adversarial attacks. To further strengthen data privacy, we integrate these data augmentation methods with data pruning techniques. Our empirical results demonstrate that the proposed approach not only improves the accuracy of federated learning models but also reduces the quality of reconstructed images, offering a higher level of data privacy protection.
Keywords:
Federated learning
Data privacy
Data augmentation
Gradient inversion attack

Journal

Applied Intelligence cover
Applied Intelligence
IF:
3.5
Papers:
7.5K
Citations:
1.7W

Organization

C
College of Computer Science
Scholars:
359
Papers: 172
Citations: 0