Surrogate Model Extension (SME): A Fast and Accurate Weight Update Attack on Federated Learning
Junyi Zhu, Ruicong Yao, Matthew B. Blaschko
摘要
In Federated Learning (FL) and many other distributed training frameworks, collaborators can hold their private data locally and only share the network weights trained with the local data after multiple iterations. Gradient inversion is a family of privacy attacks that recovers data from its generated gradients. Seemingly, FL can provide a degree of protection against gradient inversion attacks on weight updates, since the gradient of a single step is concealed by the accumulation of gradients over multiple local iterations. In this work, we propose a principled way to extend gradient inversion attacks to weight updates in FL, thereby better exposing weaknesses in the presumed privacy protection inherent in FL. In particular, we propose a surrogate model method based on the characteristic of two-dimensional gradient flow and low-rank property of local updates. Our method largely boosts the ability of gradient inversion attacks on weight updates containing many iterations and achieves state-of-the-art (SOTA) performance. Additionally, our method runs up to faster than the SOTA baseline in the common FL scenario. Our work re-evaluates and highlights the privacy risk of sharing network weights. Our code is available at https://github.com/JunyiZhu-AI/surrogate_model_extension.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- PPIDSG: A Privacy-Preserving Image Distribution Sharing Scheme with GAN in Federated LearningYuting Ma, Yuanzhi Yao, Xiaohua XuAAAI 2024 · 被引用 9 次
- Foreseeing Reconstruction Quality of Gradient Inversion: An Optimization PerspectiveHyeong Gwon Hong, Yooshin Cho, Hanbyel Cho, Jaesung Ahn 等AAAI 2024 · 被引用 3 次
- A Unified Federated Framework for Trajectory Data Preparation via LLMsZhihao Zeng, Ziquan Fang, Wei Shao, Lu Chen 等ICLR 2026
- Gradient Inversion Attacks Beyond SGDGuangnian Wan, Gongfan Fang, Xinyin Ma, Xinchao WangICML 2026
它引用的顶会 Paper20
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone 等CCS 2017 · 被引用 3,936 次
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski 等USENIX Security 2021 · 被引用 2,866 次
相关 Paper
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang 等CVPR 2021
- Enhancing Privacy Preservation in Federated Learning via Learning Rate PerturbationGuangnian Wan, Haitao Du, Xuejing Yuan, Jun Yang 等ICCV 2023 · 被引用 2 次
- More than Enough is Too Much: Adaptive Defenses against Gradient Leakage in Production Federated LearningFei Wang, Ethan Hugh, Baochun LiINFOCOM 2023 · 被引用 25 次
- A New Federated Learning Framework Against Gradient Inversion AttacksPengxin Guo, Shuang Zeng, Wenhao Chen, Xiaodan Zhang 等AAAI 2025 · 被引用 5 次
- FedInv: Byzantine-Robust Federated Learning by Inversing Local Model UpdatesBo Zhao, Peng Sun, Tao Wang, Keyu JiangAAAI 2022 · 被引用 82 次
