Towards Eliminating Hard Label Constraints in Gradient Inversion Attacks
Yanbo Wang, Jian Liang, Ran He
Abstract
Gradient inversion attacks aim to reconstruct local training data from intermediate gradients exposed in the federated learning framework. Despite successful attacks, all previous methods, starting from reconstructing a single data point and then relaxing the single-image limit to batch level, are only tested under hard label constraints. Even for single-image reconstruction, we still lack an analysis-based algorithm to recover augmented soft labels. In this work, we change the focus from enlarging batchsize to investigating the hard label constraints, considering a more realistic circumstance where label smoothing and mixup techniques are used in the training process. In particular, we are the first to initiate a novel algorithm to simultaneously recover the ground-truth augmented label and the input feature of the last fully-connected layer from single-input gradients, and provide a necessary condition for any analytical-based label recovery methods. Extensive experiments testify to the label recovery accuracy, as well as the benefits to the following image reconstruction. We believe soft labels in classification tasks are worth further attention in gradient inversion attacks 1 .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- SoK: Gradient Inversion Attacks in Federated LearningVincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella et al.USENIX Security 2025
- A Unified Federated Framework for Trajectory Data Preparation via LLMsZhihao Zeng, Ziquan Fang, Wei Shao, Lu Chen et al.ICLR 2026
- SoK: On Gradient Leakage in Federated LearningJiacheng Du, Jiahui Hu, Zhibo Wang, Peng Sun et al.USENIX Security 2025
Builds on15
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- No Fear of Heterogeneity: Classifier Calibration for Federated Learning with Non-IID DataMi Luo, Fei Chen, Dapeng Hu, Yifan Zhang et al.NeurIPS 2021 · 510 citations
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li et al.NeurIPS 2021 · 419 citations
- Gradient Inversion with Generative Image PriorJinwoo Jeon, Jaechang Kim, Kangwook Lee, Sewoong Oh et al.NeurIPS 2021 · 216 citations
Related papers
- Instance-wise Batch Label Restoration via Gradients in Federated LearningKailang Ma, Yu Sun, Jian Cui, Dawei Li et al.ICLR 2023
- Recovering Labels from Local Updates in Federated LearningHuancheng Chen, Haris VikaloICML 2024 · 9 citations
- Leak and Learn: An Attacker's Cookbook to Train Using Leaked Data from Federated LearningJoshua C. Zhao, Ahaan Dabholkar, Atul Sharma, Saurabh BagchiCVPR 2024 · 4 citations
- Generative Gradient Inversion via Over-Parameterized Networks in Federated LearningChi Zhang, Xiaoman Zhang, Ekanut Sotthiwat, Yanyu Xu et al.ICCV 2023 · 17 citations
- Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated LearningZhibo Wang, Zhiwei Chang, Jiahui Hu, Xiaoyi Pang et al.INFOCOM 2024 · 10 citations
