Paper Reading AI Learner

RAF-GI: Towards Robust, Accurate and Fast-Convergent Gradient Inversion Attack in Federated Learning

2024-03-13 09:48:04
Can Liu, Jin Wang, Dongyang Yu

Abstract

Federated learning (FL) empowers privacy-preservation in model training by only exposing users' model gradients. Yet, FL users are susceptible to the gradient inversion (GI) attack which can reconstruct ground-truth training data such as images based on model gradients. However, reconstructing high-resolution images by existing GI attack works faces two challenges: inferior accuracy and slow-convergence, especially when the context is complicated, e.g., the training batch size is much greater than 1 on each FL user. To address these challenges, we present a Robust, Accurate and Fast-convergent GI attack algorithm, called RAF-GI, with two components: 1) Additional Convolution Block (ACB) which can restore labels with up to 20% improvement compared with existing works; 2) Total variance, three-channel mEan and cAnny edge detection regularization term (TEA), which is a white-box attack strategy to reconstruct images based on labels inferred by ACB. Moreover, RAF-GI is robust that can still accurately reconstruct ground-truth data when the users' training batch size is no more than 48. Our experimental results manifest that RAF-GI can diminish 94% time costs while achieving superb inversion quality in ImageNet dataset. Notably, with a batch size of 1, RAF-GI exhibits a 7.89 higher Peak Signal-to-Noise Ratio (PSNR) compared to the state-of-the-art baselines.

Abstract (translated)

联邦学习(FL)通过仅暴露用户的模型梯度来实现模型的隐私保护。然而,FL用户易受到梯度反向(GI)攻击的攻击,该攻击可以根据模型梯度重构训练数据,如图像。然而,通过现有的GI攻击重构高分辨率图像面临着两个挑战:准确性和收敛速度,尤其是在复杂背景下,例如每个FL用户的训练批量大小远大于1。为了应对这些挑战,我们提出了一个鲁棒、准确且收敛速度快的GI攻击算法,称为RAF-GI,包含两个组件:1)附加卷积层(ACB),它可以比现有工作最多提高20%的标签恢复;2)总方差,三个通道的mEan和cCanny边缘检测正则化项(TEA),这是一种白盒攻击策略,用于根据ACB推断的标签重构图像。此外,RAF-GI具有鲁棒性,即使在用户训练批量大小不超过48时,仍能准确地重构地面真实数据。我们的实验结果表明,RAF-GI可以在ImageNet数据集上减少94%的时间开销,同时具有出色的逆向质量。值得注意的是,当批量为1时,RAF-GI显示出比最先进的基准模型高出7.89倍的峰值信号-噪声比(PSNR)。

URL

https://arxiv.org/abs/2403.08383

PDF

https://arxiv.org/pdf/2403.08383.pdf


Tags
3D Action Action_Localization Action_Recognition Activity Adversarial Agent Attention Autonomous Bert Boundary_Detection Caption Chat Classification CNN Compressive_Sensing Contour Contrastive_Learning Deep_Learning Denoising Detection Dialog Diffusion Drone Dynamic_Memory_Network Edge_Detection Embedding Embodied Emotion Enhancement Face Face_Detection Face_Recognition Facial_Landmark Few-Shot Gait_Recognition GAN Gaze_Estimation Gesture Gradient_Descent Handwriting Human_Parsing Image_Caption Image_Classification Image_Compression Image_Enhancement Image_Generation Image_Matting Image_Retrieval Inference Inpainting Intelligent_Chip Knowledge Knowledge_Graph Language_Model LLM Matching Medical Memory_Networks Multi_Modal Multi_Task NAS NMT Object_Detection Object_Tracking OCR Ontology Optical_Character Optical_Flow Optimization Person_Re-identification Point_Cloud Portrait_Generation Pose Pose_Estimation Prediction QA Quantitative Quantitative_Finance Quantization Re-identification Recognition Recommendation Reconstruction Regularization Reinforcement_Learning Relation Relation_Extraction Represenation Represenation_Learning Restoration Review RNN Robot Salient Scene_Classification Scene_Generation Scene_Parsing Scene_Text Segmentation Self-Supervised Semantic_Instance_Segmentation Semantic_Segmentation Semi_Global Semi_Supervised Sence_graph Sentiment Sentiment_Classification Sketch SLAM Sparse Speech Speech_Recognition Style_Transfer Summarization Super_Resolution Surveillance Survey Text_Classification Text_Generation Tracking Transfer_Learning Transformer Unsupervised Video_Caption Video_Classification Video_Indexing Video_Prediction Video_Retrieval Visual_Relation VQA Weakly_Supervised Zero-Shot