arXiv AI By Viktor Valadi, Lucas Beerens, Mattias {\AA}kesson, Johan \"Ostman, Fazeleh Hoseini, Salman Toor, Andreas Hellander

Practical Feasibility of Gradient Inversion Attacks in Federated Learning

Read the original on arXiv AI →

The Flow has not summarised this story yet — read it at arXiv AI.

arXiv AI
Sep 11

Cascading Gradient Inversion via LT-Code Inspired Peeling in Federated Learning

The paper introduces a new gradient inversion attack for federated learning that leverages concepts from erasure‑correcting codes to recover entire training batches and their labels from a single FedSGD round. Unlike previous analytic attacks, this method can exactly reconstruct batches of up to 128 samples on ImageNet and achieves over 90% recovery even when the attacker actively manipulates the model. The study demonstrates that federated learning’s privacy leakage is far greater than previously estimated.

By Saeed Shariati, Mohsen Alambardar Meybodi
arXiv Machine Learning
5d ago

A Path Integral Surrogate for Multi-Step Gradient Inversion in Federated Learning

The paper introduces PI‑SME, a Path‑Integral Surrogate Model Extension, to improve gradient inversion attacks in federated learning. By treating a client’s accumulated update as a path integral of the gradient field and approximating it with Gauss–Legendre quadrature over a learnable Bézier path, PI‑SME reconstructs private input images more accurately than existing surrogate baselines. Experiments on CIFAR‑100 and FEMNIST demonstrate its superior performance across various trajectory lengths and class‑restricted batches.

By Agnivo Ghosh, Saumik Bhattacharya