Practical Feasibility of Gradient Inversion Attacks in Federated Learning
Read the original on arXiv AI →The Flow has not summarised this story yet — read it at arXiv AI.
The Flow has not summarised this story yet — read it at arXiv AI.
The paper introduces a new gradient inversion attack for federated learning that leverages concepts from erasure‑correcting codes to recover entire training batches and their labels from a single FedSGD round. Unlike previous analytic attacks, this method can exactly reconstruct batches of up to 128 samples on ImageNet and achieves over 90% recovery even when the attacker actively manipulates the model. The study demonstrates that federated learning’s privacy leakage is far greater than previously estimated.
arXiv:2610.07677v1 Announce Type: new Abstract: In this paper, we show that standard evaluations of high-resolution Model Inversion Attacks (MIAs) significantly underestimate training-data privacy le...
The paper introduces PI‑SME, a Path‑Integral Surrogate Model Extension, to improve gradient inversion attacks in federated learning. By treating a client’s accumulated update as a path integral of the gradient field and approximating it with Gauss–Legendre quadrature over a learnable Bézier path, PI‑SME reconstructs private input images more accurately than existing surrogate baselines. Experiments on CIFAR‑100 and FEMNIST demonstrate its superior performance across various trajectory lengths and class‑restricted batches.
In this paper, we show that standard evaluations of high-resolution Model Inversion Attacks (MIAs) significantly underestimate training-data privacy leakage. State-of-the-art privacy defenses, standar...
arXiv:2607. 12354v1 Announce Type: new Abstract: In this paper, we challenge the prevailing view that information dependency (including rote memorization) drives training data exposure to image reconstruction attacks.
arXiv:2409. 01062v4 Announce Type: replace Abstract: Model Inversion (MI) attacks pose a significant privacy threat by reconstructing private training data from machine learning models.