Venom: Liquid Diffusion-Guided Gradient Inversion for Breaking Differential Privacy in Federated Learning
Bin Hu, Jingling Yuan, Jiawei Jiang, Chuang Hu
Abstract
Gradient perturbation mechanisms, such as differential privacy (DP), aim to defend against gradient inversion attacks (GIA) by injecting noise into the shared gradients. Recent studies have shown that DP-based defenses lack robustness against advanced GIAs. However, existing gradient inversion methods typically rely on iterative refinement and assume static noise, resulting in low efficiency and limited reconstruction fidelity under high-noise conditions. In this paper, we propose Venom, a novel gradient inversion attack method based on a liquid diffusion mechanism. Venom reconstructs private data directly from DP-protected gradients without requiring any prior knowledge of the noise distribution. Specifically, we design a Structural Prior Extraction (SPE) module that analytically extracts deep feature representations from perturbed gradients through energy-based aggregation, enabling stable pre-reconstruction of users' latent data features. We further introduce a Diffusion-driven Liquid Recovery Network (Diff-LRN) for high-fidelity image reconstruction. Unlike traditional diffusion models that rely on iterative sampling with predefined noise schedules, Diff-LRN performs deterministic single-step reconstruction using adaptive liquid neural dynamics to handle spatially heterogeneous noise patterns. Experiments across four benchmarks demonstrate that Venom achieves an speedup of up to 38,315× over state-of-the-art attacks while maintaining high reconstruction fidelity under strong DP settings. These results challenge prevailing assumptions about DP robustness and underscore the need for more resilient privacy-preserving mechanisms in federated learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on6
- Liquid Time-constant NetworksRamin M. Hasani, Mathias Lechner, Alexander Amini, Daniela Rus et al.AAAI 2021 · 399 citations
- Fishing for User Data in Large-Batch Federated Learning via Gradient MagnificationYuxin Wen, Jonas Geiping, Liam Fowl, Micah Goldblum et al.ICML 2022 · 119 citations
- More than Enough is Too Much: Adaptive Defenses against Gradient Leakage in Production Federated LearningFei Wang, Ethan Hugh, Baochun LiINFOCOM 2023 · 25 citations
- Mjölnir: Breaking the Shield of Perturbation-Protected Gradients via Adaptive DiffusionXuan Liu, Siqi Cai, Qihua Zhou, Song Guo et al.AAAI 2025 · 4 citations
- Uncovering Gradient Inversion Risks in Practical Language Model TrainingXinguo Feng, Zhongkui Ma, Zihan Wang, Eu Joe Chegne et al.CCS 2024 · 2 citations
Related papers
- Enhanced Privacy Leakage from Noise-Perturbed Gradients via Gradient-Guided Conditional Diffusion ModelsJiayang Meng, Tao Huang, Hong Chen, Chen Hou et al.AAAI 2026 · 1 citation
- Towards the Robustness of Differentially Private Federated LearningTao Qi, Huili Wang, Yongfeng HuangAAAI 2024 · 30 citations
- Federated Learning Vulnerabilities: Privacy Attacks with Denoising Diffusion Probabilistic ModelsHongyan Gu, Xinyi Zhang, Jiang Li, Hui Wei et al.WWW 2024 · 17 citations
- GRASP: Differentially Private Graph Reconstruction Defense with Structured PerturbationZhiyu Guo, Yang Liu, Xiang Ao, Qing HeKDD 2025 · 3 citations
- GIFD: A Generative Gradient Inversion Method with Feature Domain OptimizationHao Fang, Bin Chen, Xuan Wang, Zhi Wang et al.ICCV 2023 · 62 citations
