More than Enough is Too Much: Adaptive Defenses against Gradient Leakage in Production Federated Learning
Fei Wang, Ethan Hugh, Baochun Li
Abstract
With increasing concerns on privacy leakage from gradients, a variety of attack mechanisms emerged to recover private data from gradients at an honest-but-curious server, which challenged the primary advantage of privacy protection in federated learning. However, we cast doubt upon the real impact of these gradient attacks on production federated learning systems. By taking away several impractical assumptions that the literature has made, we find that gradient attacks pose a limited degree of threat to the privacy of raw data.Through a comprehensive evaluation on existing gradient attacks in a federated learning system with practical assumptions, we have systematically analyzed their effectiveness under a wide range of configurations. We present key priors required to make the attack possible or stronger, such as a narrow distribution of initial model weights, as well as inversion at early stages of training. We then propose a new lightweight defense mechanism that provides sufficient and self-adaptive protection against time-varying levels of the privacy leakage risk throughout the federated learning process. As a variation of gradient perturbation method, our proposed defense, called Outpost, selectively adds Gaussian noise to gradients at each update iteration according to the Fisher information matrix, where the level of noise is determined by the privacy leakage risk quantified by the spread of model weights at each layer. To limit the computation overhead and training performance degradation, Outpost only performs perturbation with iteration-based decay. Our experimental results demonstrate that Outpost can achieve a much better tradeoff than the state-of-the-art with respect to convergence performance, computational overhead, and protection against gradient attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 27c6a849-6ffb-442a-8194-ba0bd6f56ed2Cited by top-tier papers15
- Understanding Deep Gradient Leakage via Inversion Influence FunctionsHaobo Zhang, Junyuan Hong, Yuyang Deng, Mehrdad Mahdavi et al.NeurIPS 2023 · 16 citations
- Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient AttacksLulu Xue, Shengshan Hu, Ruizhi Zhao, Leo Yu Zhang et al.AAAI 2024 · 10 citations
- FedMobile: Enabling Knowledge Contribution-aware Multi-modal Federated Learning with Incomplete ModalitiesYi Liu, Cong Wang, Xingliang YuanWWW 2025 · 9 citations
- Lightweight Federated Learning with Differential Privacy and Straggler ResilienceShu Hong, Xiaojun Lin, Lingjie DuanINFOCOM 2025 · 7 citations
- BadSampler: Harnessing the Power of Catastrophic Forgetting to Poison Byzantine-robust Federated LearningYi Liu, Cong Wang, Xingliang YuanKDD 2024 · 5 citations
Builds on9
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li et al.NeurIPS 2021 · 419 citations
- Gradient Inversion with Generative Image PriorJinwoo Jeon, Jaechang Kim, Kangwook Lee, Sewoong Oh et al.NeurIPS 2021 · 216 citations
- Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified ModelsLiam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum et al.ICLR 2022 · 181 citations
Related papers
- Protect Privacy from Gradient Leakage Attack in Federated LearningJunxiao Wang, Song Guo, Xin Xie, Heng QiINFOCOM 2022 · 82 citations
- Surrogate Model Extension (SME): A Fast and Accurate Weight Update Attack on Federated LearningJunyi Zhu, Ruicong Yao, Matthew B. BlaschkoICML 2023 · 17 citations
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang et al.CVPR 2021
- Dropout Is NOT All You Need to Prevent Gradient LeakageDaniel Scheliga, Patrick Maeder, Marco SeelandAAAI 2023 · 22 citations
- Enhancing Privacy Preservation in Federated Learning via Learning Rate PerturbationGuangnian Wan, Haitao Du, Xuejing Yuan, Jun Yang et al.ICCV 2023 · 2 citations
