arrow
Return

An effective and practical gradient inversion attack

delete2022-08-19
delete4
delete
OA
AI
Z
Zeren Luo
C
Chuangwei Zhu
L
Lujie Fang
G
Guang Kou
R
Ruitao Hou
X
Xianmin Wang *
DOI:10.1002/int.22997delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
While gradient aggregation playing a vital role in federated or collaborative learning, recent studies have revealed that gradient aggregation may suffer from some attacks, such as gradient inversion, where the private training data can be recovered from the shared gradients. However, the performance of the existing attack methods is limited because they usually require prior knowledge in Batch Normalization and could only reconstruct a single image or a small batch one. To make the attacks less restrictive and more applicable, we propose an effective and practical gradient inversion method in this paper. Specifically, we use cosine similarity to measure the difference of gradients between the synthesized and ground-truth images, and then construct an input regularization for the fully connected layer to ensure the fidelity of the image. Moreover, we apply the total variation denoising strategy to the convolution feature map for further improving the smoothness of the reconstructed image. Experimental results demonstrate that our method can reconstruct high fidelity training data on a large batch size for complex data sets, such as ImageNet.
Keywords:
federated learning
gradient sharing
machine learning
privacy protection

Journal

International Journal of Intelligent Systems cover
International Journal of Intelligent Systems
IF:
3.7
Papers:
3.1K
Citations:
8.1K

Organization

G
Guangzhou University
Scholars:
1.8W
Papers: 1.3W
Citations: 1.8W
Cited Papers

Cited Papers

Parkinson's disease: Nigral receptor changes support peptidergic role in nigrostriatal modulation
err2004-10-08
err0
PREAI
errGeorge R. Uhl; Gail O. Hackney; Mary Torchia; Victoria Stranov; Wallace W. Tourtellotte; Peter J. Whitehouse; Vinh Tran; Steven Strittmatter
errShare
errSave
Hybrid sequence-based Android malware detection using natural language processing
err2021-07-12
err47
errOAAI
errZhang, Nan; Xue, Jingfeng; Ma, Yuxi; Zhang, Ruyun; Liang, Tiancai; Tan, Yu-an
errShare
errSave
ELAA: An efficient local adversarial attack using model interpreters
err2021-09-19
err5
errOAAI
errGuo, Shangwei; Geng, Siyuan; Xiang, Tao; Liu, Hangcheng; Hou, Ruitao
errShare
errSave
Federated Machine Learning: Concept and Applications
err2019-01-28
err5.5K
PREAI
errYang, Qiang; Liu, Yang; Chen, Tianjian; Tong, Yongxin
errShare
errSave
errShare
errSave
Adversarial attacks on deep-learning-based SAR image target recognition
err2020-07-01
err86
PREAI
errHuang, Teng; Zhang, Qixiang; Liu, Jiabao; Hou, Ruitao; Wang, Xianmin; Li, Ya
errShare
errSave
researcher View more