Instance-wise Batch Label Restoration via Gradients in Federated Learning
Kailang Ma, Yu Sun, Jian Cui, Dawei Li, Zhenyu Guan, Jianwei Liu
Abstract
Gradient inversion attacks have posed a serious threat to the privacy of federated learning. The attacks search for the optimal pair of input and label best matching the shared gradients and the search space of the attacks can be reduced by pre-restoring labels. Recently, label restoration technique allows for the extraction of labels from gradients analytically, but even the state-of-the-art remains limited to identify the presence of categories (i.e., the class-wise label restoration). This work considers the more real-world settings, where there are multiple instances of each class in a training batch. An analytic method is proposed to perform instance-wise batch label restoration from only the gradient of the final layer. On the basis of the approximate recovered class-wise embeddings and post-softmax probabilities, we establish linear equations of the gradients, probabilities and labels to derive the Number of Instances (NoI) per class by the Moore-Penrose pseudoinverse algorithm. Our experimental evaluations reach over 99% Label existence Accuracy (LeAcc) and exceed 96% Label number Accuracy (LnAcc) in most cases on three image datasets and four classification models. The two metrics are used to evaluate class-wise and instance-wise label restoration accuracy, respectively. And the recovery is made feasible even with a batch size of 4096 and partially negative activations (e.g., Leaky ReLU and Swish). Furthermore, we demonstrate that our method facilitates the existing gradient inversion attacks by exploiting the recovered labels, with an increase of 6-7 in PSNR on both MNIST and CIFAR100. Our code isavailable at https://github.com/BUAA-CST/iLRG.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 22598092-9df8-447e-9811-34b7f715bdf5Cited by top-tier papers11
- GIFD: A Generative Gradient Inversion Method with Feature Domain OptimizationHao Fang, Bin Chen, Xuan Wang, Zhi Wang et al.ICCV 2023 · 62 citations
- Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated LearningZhibo Wang, Zhiwei Chang, Jiahui Hu, Xiaoyi Pang et al.INFOCOM 2024 · 10 citations
- Recovering Labels from Local Updates in Federated LearningHuancheng Chen, Haris VikaloICML 2024 · 9 citations
- Towards Eliminating Hard Label Constraints in Gradient Inversion AttacksYanbo Wang, Jian Liang, Ran HeICLR 2024 · 7 citations
- A New Federated Learning Framework Against Gradient Inversion AttacksPengxin Guo, Shuang Zeng, Wenhao Chen, Xiaodan Zhang et al.AAAI 2025 · 5 citations
Related papers
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li et al.NeurIPS 2021 · 419 citations
- ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning Through Activation RecoveryZirui Gong, Leo Yu Zhang, Yanjun Zhang, Viet Vo et al.S&P 2026
- See Through Gradients: Image Batch Recovery via GradInversionHongxu Yin, Arun Mallya, Arash Vahdat, José M. Álvarez et al.CVPR 2021
- Generative Gradient Inversion via Over-Parameterized Networks in Federated LearningChi Zhang, Xiaoman Zhang, Ekanut Sotthiwat, Yanyu Xu et al.ICCV 2023 · 17 citations
- Enhanced Privacy Leakage from Noise-Perturbed Gradients via Gradient-Guided Conditional Diffusion ModelsJiayang Meng, Tao Huang, Hong Chen, Chen Hou et al.AAAI 2026 · 1 citation
