Gradient Inversion Attacks Beyond SGD
Guangnian Wan, Gongfan Fang, Xinyin Ma, Xinchao Wang
Abstract
Gradient Inversion Attack (GIA) poses a significant threat to federated learning, enabling adversaries to reconstruct private training data from the information shared during training. Prior research has predominantly focused on the vanilla SGD, where the server or an eavesdropper can directly observe true gradients. In practical deployments, however, models may be trained with adaptive optimizers (e.g., Adam, RMSProp, and AdaGrad), for which the observable signal is not raw gradients but momentum-based parameter updates. This setting remains underexplored and undermines traditional gradient-matching strategies, which struggle to recover labels and images from non-gradient updates. To address this gap, this paper explores attacks tailored to modern adaptive optimizers. We present an analytical rule for recovering labels from optimizer updates and propose an update-matching objective that optimizes dummy inputs to reproduce the observed updates. The proposed approach is general and can be directly applied to various optimizers such as Adam, AdaGrad, and RMSProp. Furthermore, we find that, despite being introduced for adaptive optimizers, the proposed objective function also yields stronger attacks in the standard SGD setting. Experiments on datasets such as ImageNet and PACS highlight the effectiveness of our method over existing gradient matching techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on20
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Adaptive Federated OptimizationSashank J. Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett et al.ICLR 2021 · 1,917 citations
- STaR: Bootstrapping Reasoning With ReasoningEric Zelikman, Yuhuai Wu, Jesse Mu, Noah D. GoodmanNeurIPS 2022 · 1,126 citations
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li et al.NeurIPS 2021 · 419 citations
- Gradient Inversion with Generative Image PriorJinwoo Jeon, Jaechang Kim, Kangwook Lee, Sewoong Oh et al.NeurIPS 2021 · 216 citations
Related papers
- Recovering Labels from Local Updates in Federated LearningHuancheng Chen, Haris VikaloICML 2024 · 9 citations
- Foreseeing Reconstruction Quality of Gradient Inversion: An Optimization PerspectiveHyeong Gwon Hong, Yooshin Cho, Hanbyel Cho, Jaesung Ahn et al.AAAI 2024 · 3 citations
- Revealing and Protecting Labels in Distributed TrainingTrung Dang, Om Thakkar, Swaroop Ramaswamy, Rajiv Mathews et al.NeurIPS 2021 · 35 citations
- On the Detectability of Active Gradient Inversion Attacks in Federated LearningVincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella et al.S&P 2026 · 1 citation
- Good Gradients Poison Your Model: Evading Defenses in Federated Learning via Boundary-adaptive PerturbationXiaojie Zhao, Jinqiao Shi, Yi Li, Junmin Huang et al.AAAI 2026
