跳到主要导航 跳到搜索 跳到主要内容

Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings

  • Mingyuan Fan
  • , Fuyi Wang
  • , Cen Chen*
  • , Jianying Zhou
  • *此作品的通讯作者
  • East China Normal University
  • Royal Melbourne Institute of Technology University
  • Singapore University of Technology and Design

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Federated learning (FL) enables collaborative model training among multiple clients without the need to expose raw data. Its ability to safeguard privacy, at the heart of FL, has recently been a hot-button debate topic. To elaborate, several studies have introduced a type of attacks known as gradient leakage attacks (GLAs), which exploit the gradients shared during training to reconstruct clients’ raw data. On the flip side, some literature, however, contends no substantial privacy risk in practical FL environments due to the effectiveness of such GLAs being limited to overly relaxed conditions, such as small batch sizes and knowledge of clients’ data distributions. This paper bridges this critical gap by empirically demonstrating that clients’ data can still be effectively reconstructed, even within realistic FL environments. Upon revisiting GLAs, we recognize that their performance failures stem from their inability to handle the gradient matching problem. To alleviate the performance bottlenecks identified above, we develop FEDLEAK, which introduces two novel techniques, partial gradient matching and gradient regularization. Moreover, to evaluate the performance of FEDLEAK in real-world FL environments, we formulate a practical evaluation protocol grounded in a thorough review of extensive FL literature and industry practices. Under this protocol, FEDLEAK can still achieve high-fidelity data reconstruction, thereby underscoring the significant vulnerability in FL systems and the urgent need for more effective defense methods.

源语言英语
主期刊名Proceedings of the 34th USENIX Security Symposium
出版商USENIX Association
2985-3004
页数20
ISBN(电子版)9781939133526
出版状态已出版 - 2025
活动34th USENIX Security Symposium, USENIX Security 2025 - Seattle, 美国
期限: 13 8月 202515 8月 2025

出版系列

姓名Proceedings of the 34th USENIX Security Symposium

会议

会议34th USENIX Security Symposium, USENIX Security 2025
国家/地区美国
Seattle
时期13/08/2515/08/25

指纹

探究 'Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings' 的科研主题。它们共同构成独一无二的指纹。

引用此