On the Detectability of Active Gradient Inversion Attacks in Federated Learning
Vincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella, Mario Vento
Abstract
One of the key advantages of Federated Learning (FL) is its ability to collaboratively train a Machine Learning (ML) model while keeping clients' data on-site. However, this can create a false sense of security. Despite not sharing private data increases the overall privacy, prior studies have shown that gradients exchanged during the FL training remain vulnerable to Gradient Inversion Attacks (GIAs). These attacks allow the reconstruction of the clients' local data, breaking the privacy promise of FL. GIAs can be launched by either a passive or an active server. In the latter case, a malicious server manipulates the global model to facilitate data reconstruction. While effective, earlier attacks falling under this category have been demonstrated to be detectable by clients, limiting their real-world applicability. Recently, novel active GIAs have emerged, claiming to be far stealthier than previous approaches. This work provides the first comprehensive analysis of these claims, investigating four state-of-the-art GIAs. We propose novel lightweight client-side detection techniques, based on statistically improbable weight structures and anomalous loss and gradient dynamics. Extensive evaluation across several configurations demonstrates that our methods enable clients to effectively detect active GIAs without any modifications to the FL training protocol.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on9
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified ModelsLiam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum et al.ICLR 2022 · 181 citations
- Fishing for User Data in Large-Batch Federated Learning via Gradient MagnificationYuxin Wen, Jonas Geiping, Liam Fowl, Micah Goldblum et al.ICML 2022 · 119 citations
- Loki: Large-scale Data Reconstruction Attack against Federated Learning through Model ManipulationJoshua C. Zhao, Atul Sharma, Ahmed Roushdy Elkordy, Yahya H. Ezzeldin et al.S&P 2024 · 64 citations
- Hiding in Plain Sight: Disguising Data Stealing Attacks in Federated LearningKostadin Garov, Dimitar Iliev Dimitrov, Nikola Jovanovic, Martin T. VechevICLR 2024 · 13 citations
Related papers
- SoK: On Gradient Leakage in Federated LearningJiacheng Du, Jiahui Hu, Zhibo Wang, Peng Sun et al.USENIX Security 2025
- SoK: Gradient Inversion Attacks in Federated LearningVincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella et al.USENIX Security 2025
- ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning Through Activation RecoveryZirui Gong, Leo Yu Zhang, Yanjun Zhang, Viet Vo et al.S&P 2026
- Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated LearningZhibo Wang, Zhiwei Chang, Jiahui Hu, Xiaoyi Pang et al.INFOCOM 2024 · 10 citations
- Attribute Inference Attacks for Federated Regression TasksFrancesco Diana, Othmane Marfoq, Chuan Xu, Giovanni Neglia et al.AAAI 2025 · 2 citations
