Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings
Mingyuan Fan, Fuyi Wang, Cen Chen, Jianying Zhou
摘要
Federated learning (FL) enables collaborative model training among multiple clients without the need to expose raw data. Its ability to safeguard privacy, at the heart of FL, has recently been a hot-button debate topic. To elaborate, several studies have introduced a type of attacks known as gradient leakage attacks (GLAs), which exploit the gradients shared during training to reconstruct clients' raw data. On the flip side, some literature, however, contends no substantial privacy risk in practical FL environments due to the effectiveness of such GLAs being limited to overly relaxed conditions, such as small batch sizes and knowledge of clients' data distributions. This paper bridges this critical gap by empirically demonstrating that clients' data can still be effectively reconstructed, even within realistic FL environments. Upon revisiting GLAs, we recognize that their performance failures stem from their inability to handle the gradient matching problem. To alleviate the performance bottlenecks identified above, we develop FEDLEAK, which introduces two novel techniques, partial gradient matching and gradient regularization. Moreover, to evaluate the performance of FEDLEAK in real-world FL environments, we formulate a practical evaluation protocol grounded in a thorough review of extensive FL literature and industry practices. Under this protocol, FEDLEAK can still achieve high-fidelity data reconstruction, thereby underscoring the significant vulnerability in FL systems and the urgent need for more effective defense methods.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Cracking Federated Privacy: Initialization-Resilient Gradient Inversion with Fine-Grained ReconstructionKaiming Zhu, Jinsheng Yang, Siyang Guo, Huaqian Qin 等USENIX Security 2026
- ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning Through Activation RecoveryZirui Gong, Leo Yu Zhang, Yanjun Zhang, Viet Vo 等S&P 2026
它引用的顶会 Paper26
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone 等CCS 2017 · 被引用 3,936 次
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang 等ICLR 2020 · 被引用 2,930 次
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski 等USENIX Security 2021 · 被引用 2,866 次
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 被引用 2,107 次
相关 Paper
- Fast Generation-Based Gradient Leakage Attacks against Highly Compressed GradientsDongyun Xue, Haomiao Yang, Mengyu Ge, Jingwei Li 等INFOCOM 2023 · 被引用 4 次
- SoK: On Gradient Leakage in Federated LearningJiacheng Du, Jiahui Hu, Zhibo Wang, Peng Sun 等USENIX Security 2025
- Protect Privacy from Gradient Leakage Attack in Federated LearningJunxiao Wang, Song Guo, Xin Xie, Heng QiINFOCOM 2022 · 被引用 82 次
- Refiner: Data Refining against Gradient Leakage Attacks in Federated LearningMingyuan Fan, Cen Chen, Chengyu Wang, Xiaodan Li 等USENIX Security 2025
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang 等CVPR 2021
