arXiv Machine Learning By Agnivo Ghosh, Saumik Bhattacharya

A Path Integral Surrogate for Multi-Step Gradient Inversion in Federated Learning

Read the original on arXiv Machine Learning →

The paper introduces PI‑SME, a Path‑Integral Surrogate Model Extension, to improve gradient inversion attacks in federated learning. By treating a client’s accumulated update as a path integral of the gradient field and approximating it with Gauss–Legendre quadrature over a learnable Bézier path, PI‑SME reconstructs private input images more accurately than existing surrogate baselines. Experiments on CIFAR‑100 and FEMNIST demonstrate its superior performance across various trajectory lengths and class‑restricted batches.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Machine Learning.

arXiv AI
Sep 11

Cascading Gradient Inversion via LT-Code Inspired Peeling in Federated Learning

The paper introduces a new gradient inversion attack for federated learning that leverages concepts from erasure‑correcting codes to recover entire training batches and their labels from a single FedSGD round. Unlike previous analytic attacks, this method can exactly reconstruct batches of up to 128 samples on ImageNet and achieves over 90% recovery even when the attacker actively manipulates the model. The study demonstrates that federated learning’s privacy leakage is far greater than previously estimated.

By Saeed Shariati, Mohsen Alambardar Meybodi
arXiv AI
Oct 1

Aegis: Generative Gradient Masking for Privacy-Preserving Medical Federated Learning

Aegis is a client‑side defense for medical federated learning that protects against model inversion attacks by adding a masking gradient derived from locally synthesized data. The method exploits the fact that attacks fail when the effective batch size exceeds the model’s leakage capacity, turning this bottleneck into a privacy guarantee. Experiments on MNIST, CIFAR‑10, and MedMNIST datasets show that Aegis neutralizes state‑of‑the‑art attacks while preserving model accuracy and adding only modest overhead.

By Chaoyu Zhang, Shanghao Shi, Heng Jin, Ning Wang, Y. Thomas Hou, Wenjing Lou
Hugging Face Trending Papers
Jun 1

IntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning

Heterogeneous Differential Privacy (HDP) in Federated Learning (FL) allows clients to select individual privacy budgets ($\varepsilon_i$) according to institutional policies and data sensitivity. In practice, many HDP-FL systems employ $\varepsilon$-aware server aggregation to improve model utility by re-weighting client updates according to their declared privacy budgets.