Mjölnir: Breaking the Shield of Perturbation-Protected Gradients via Adaptive Diffusion
Xuan Liu, Siqi Cai, Qihua Zhou, Song Guo, Ruibin Li, Kaiwei Lin
Abstract
Perturbation-based mechanisms, such as differential privacy, mitigate gradient leakage attacks by introducing noise into the gradients, thereby preventing attackers from reconstructing clients' private data from the leaked gradients. However, can gradient perturbation protection mechanisms truly defend against all gradient leakage attacks? In this paper, we present the first attempt to break the shield of gradient perturbation protection in Federated Learning for the extraction of private information. We focus on common noise distributions, specifically Gaussian and Laplace, and apply our approach to DNN and CNN models. We introduce Mjölnir, a perturbation-resilient gradient leakage attack that is capable of removing perturbations from gradients without requiring additional access to the original model structure or external data. Specifically, we leverage the inherent diffusion properties of gradient perturbation protection to develop a novel diffusion-based gradient denoising model for Mjölnir. By constructing a surrogate client model that captures the structure of perturbed gradients, we obtain crucial gradient data for training the diffusion model. We further utilize the insight that monitoring disturbance levels during the reverse diffusion process can enhance gradient denoising capabilities, allowing Mjölnir to generate gradients that closely approximate the original, unperturbed versions through adaptive sampling steps. Extensive experiments demonstrate that Mjölnir effectively recovers the protected gradients and exposes the Federated Learning process to the threat of gradient leakage, achieving superior performance in gradient denoising and private data recovery.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- SoK: Gradient Inversion Attacks in Federated LearningVincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella et al.USENIX Security 2025
- Venom: Liquid Diffusion-Guided Gradient Inversion for Breaking Differential Privacy in Federated LearningBin Hu, Jingling Yuan, Jiawei Jiang, Chuang HuAAAI 2026
Builds on8
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- BatchCrypt: Efficient Homomorphic Encryption for Cross-Silo Federated LearningChengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang et al.USENIX ATC 2020 · 967 citations
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li et al.NeurIPS 2021 · 419 citations
- AP-BSN: Self-Supervised Denoising for Real-World Images via Asymmetric PD and Blind-Spot NetworkWooseok Lee, Sanghyun Son, Kyoung Mu LeeCVPR 2022 · 148 citations
- More than Enough is Too Much: Adaptive Defenses against Gradient Leakage in Production Federated LearningFei Wang, Ethan Hugh, Baochun LiINFOCOM 2023 · 25 citations
Related papers
- Enhanced Privacy Leakage from Noise-Perturbed Gradients via Gradient-Guided Conditional Diffusion ModelsJiayang Meng, Tao Huang, Hong Chen, Chen Hou et al.AAAI 2026 · 1 citation
- Dropout Is NOT All You Need to Prevent Gradient LeakageDaniel Scheliga, Patrick Maeder, Marco SeelandAAAI 2023 · 22 citations
- Protect Privacy from Gradient Leakage Attack in Federated LearningJunxiao Wang, Song Guo, Xin Xie, Heng QiINFOCOM 2022 · 82 citations
- Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL SettingsMingyuan Fan, Fuyi Wang, Cen Chen, Jianying ZhouUSENIX Security 2025
- Gradient Inversion with Generative Image PriorJinwoo Jeon, Jaechang Kim, Kangwook Lee, Sewoong Oh et al.NeurIPS 2021 · 216 citations
