More than Enough is Too Much: Adaptive Defenses against Gradient Leakage in Production Federated Learning
Fei Wang, Ethan Hugh, Baochun Li
摘要
With increasing concerns on privacy leakage from gradients, a variety of attack mechanisms emerged to recover private data from gradients at an honest-but-curious server, which challenged the primary advantage of privacy protection in federated learning. However, we cast doubt upon the real impact of these gradient attacks on production federated learning systems. By taking away several impractical assumptions that the literature has made, we find that gradient attacks pose a limited degree of threat to the privacy of raw data.Through a comprehensive evaluation on existing gradient attacks in a federated learning system with practical assumptions, we have systematically analyzed their effectiveness under a wide range of configurations. We present key priors required to make the attack possible or stronger, such as a narrow distribution of initial model weights, as well as inversion at early stages of training. We then propose a new lightweight defense mechanism that provides sufficient and self-adaptive protection against time-varying levels of the privacy leakage risk throughout the federated learning process. As a variation of gradient perturbation method, our proposed defense, called Outpost, selectively adds Gaussian noise to gradients at each update iteration according to the Fisher information matrix, where the level of noise is determined by the privacy leakage risk quantified by the spread of model weights at each layer. To limit the computation overhead and training performance degradation, Outpost only performs perturbation with iteration-based decay. Our experimental results demonstrate that Outpost can achieve a much better tradeoff than the state-of-the-art with respect to convergence performance, computational overhead, and protection against gradient attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Understanding Deep Gradient Leakage via Inversion Influence FunctionsHaobo Zhang, Junyuan Hong, Yuyang Deng, Mehrdad Mahdavi 等NeurIPS 2023 · 被引用 16 次
- Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient AttacksLulu Xue, Shengshan Hu, Ruizhi Zhao, Leo Yu Zhang 等AAAI 2024 · 被引用 10 次
- FedMobile: Enabling Knowledge Contribution-aware Multi-modal Federated Learning with Incomplete ModalitiesYi Liu, Cong Wang, Xingliang YuanWWW 2025 · 被引用 9 次
- Lightweight Federated Learning with Differential Privacy and Straggler ResilienceShu Hong, Xiaojun Lin, Lingjie DuanINFOCOM 2025 · 被引用 7 次
- BadSampler: Harnessing the Power of Catastrophic Forgetting to Poison Byzantine-robust Federated LearningYi Liu, Cong Wang, Xingliang YuanKDD 2024 · 被引用 5 次
它引用的顶会 Paper9
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang 等ICLR 2020 · 被引用 2,930 次
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 被引用 1,822 次
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li 等NeurIPS 2021 · 被引用 419 次
- Gradient Inversion with Generative Image PriorJinwoo Jeon, Jaechang Kim, Kangwook Lee, Sewoong Oh 等NeurIPS 2021 · 被引用 216 次
- Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified ModelsLiam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum 等ICLR 2022 · 被引用 181 次
相关 Paper
- Protect Privacy from Gradient Leakage Attack in Federated LearningJunxiao Wang, Song Guo, Xin Xie, Heng QiINFOCOM 2022 · 被引用 82 次
- Surrogate Model Extension (SME): A Fast and Accurate Weight Update Attack on Federated LearningJunyi Zhu, Ruicong Yao, Matthew B. BlaschkoICML 2023 · 被引用 17 次
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang 等CVPR 2021
- Dropout Is NOT All You Need to Prevent Gradient LeakageDaniel Scheliga, Patrick Maeder, Marco SeelandAAAI 2023 · 被引用 22 次
- Enhancing Privacy Preservation in Federated Learning via Learning Rate PerturbationGuangnian Wan, Haitao Du, Xuejing Yuan, Jun Yang 等ICCV 2023 · 被引用 2 次
