USENIX Security2025Top-tier venue
Refiner: Data Refining against Gradient Leakage Attacks in Federated Learning
Mingyuan Fan, Cen Chen, Chengyu Wang, Xiaodan Li, Wenmeng Zhou
Abstract
Recent works highlight the vulnerability of Federated Learning (FL) systems to gradient leakage attacks, where attackers reconstruct clients' data from shared gradients, undermining FL's privacy guarantees. However, existing defenses show limited resilience against sophisticated attacks. This paper introduces a novel defensive paradigm that departs from conventional gradient perturbation approaches and instead focuses on the construction of robust data. Our theoretical analysis indicates such data, which exhibits low semantic similarity to the clients' raw data while maintaining good gradient alignment to clients' raw data, is able to effectively obfuscate attackers and yet maintain model performance. We refer to such data as robust data, and to generate it, we design Refiner that jointly optimizes two metrics for privacy protection and performance maintenance. The utility metric promotes the gradient consistency of key parameters between robust data and clients' data, while the privacy metric guides the generation of robust data towards enlarging the semantic gap with clients' data. Extensive empirical evaluations on multiple benchmark datasets demonstrate the superior performance of Refiner at defending against state-of-the-art attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e36228b1-1700-437e-a7f4-e0eab29a00f5Cited by top-tier papers1
Ask how each one uses itBuilds on19
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
Related papers
- Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL SettingsMingyuan Fan, Fuyi Wang, Cen Chen, Jianying ZhouUSENIX Security 2025
- Towards the Robustness of Differentially Private Federated LearningTao Qi, Huili Wang, Yongfeng HuangAAAI 2024 · 30 citations
- Gradient Obfuscation Gives a False Sense of Security in Federated LearningKai Yue, Richeng Jin, Chau-Wai Wong, Dror Baron et al.USENIX Security 2023
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang et al.CVPR 2021
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li et al.NeurIPS 2021 · 419 citations
