Understanding Deep Gradient Leakage via Inversion Influence Functions
Haobo Zhang, Junyuan Hong, Yuyang Deng, Mehrdad Mahdavi, Jiayu Zhou
Abstract
Deep Gradient Leakage (DGL) is a highly effective attack that recovers private training images from gradient vectors. This attack casts significant privacy challenges on distributed learning from clients with sensitive data, where clients are required to share gradients. Defending against such attacks requires but lacks an understanding of when and how privacy leakage happens, mostly because of the black-box nature of deep networks. In this paper, we propose a novel Inversion Influence Function (I 2 F) that establishes a closed-form connection between the recovered images and the private gradients by implicitly solving the DGL problem. Compared to directly solving DGL, I 2 F is scalable for analyzing deep networks, requiring only oracle access to gradients and Jacobian-vector products. We empirically demonstrate that I 2 F effectively approximated the DGL generally on different model architectures, datasets, modalities, attack implementations, and perturbation-based defenses. With this novel tool, we provide insights into effective gradient perturbation directions, the unfairness of privacy protection, and privacy-preferred model initialization. Our codes are provided in https://github.com/illidanlab/inversion-influence-function .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a660b3f8-965d-4998-b5f8-0848acc9692dCited by top-tier papers4
- Federated Black-Box Adaptation for Semantic SegmentationJay N. Paranjape, Shameema Sikder, S. Swaroop Vedula, Vishal M. PatelNeurIPS 2024 · 4 citations
- SoK: Gradient Inversion Attacks in Federated LearningVincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella et al.USENIX Security 2025
- Cracking Federated Privacy: Initialization-Resilient Gradient Inversion with Fine-Grained ReconstructionKaiming Zhu, Jinsheng Yang, Siyang Guo, Huaqian Qin et al.USENIX Security 2026
- FedMOP: Achieving Enhanced Privacy and Performance in Federated Learning via Momentum Orthogonal ProjectionYunlong Zhao, Xiaoheng Deng, Hongyan Xu, Zhuohua Qiu et al.CVPR 2026
Builds on19
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Estimating Training Data Influence by Tracing Gradient DescentGarima Pruthi, Frederick Liu, Satyen Kale, Mukund SundararajanNeurIPS 2020 · 784 citations
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li et al.NeurIPS 2021 · 419 citations
- On the Iteration Complexity of Hypergradient ComputationRiccardo Grazzi, Luca Franceschi, Massimiliano Pontil, Saverio SalzoICML 2020 · 241 citations
Related papers
- Dropout Is NOT All You Need to Prevent Gradient LeakageDaniel Scheliga, Patrick Maeder, Marco SeelandAAAI 2023 · 22 citations
- The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural NetworksYuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang et al.CVPR 2020
- GIFD: A Generative Gradient Inversion Method with Feature Domain OptimizationHao Fang, Bin Chen, Xuan Wang, Zhi Wang et al.ICCV 2023 · 62 citations
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang et al.CVPR 2021
- Mjölnir: Breaking the Shield of Perturbation-Protected Gradients via Adaptive DiffusionXuan Liu, Siqi Cai, Qihua Zhou, Song Guo et al.AAAI 2025 · 4 citations
