paper-with-me

홈 › Papers

A Theoretical Insight into Attack and Defense of Gradient Leakage in Transformer

2023-11-22 · Chenyang Li, Zhao Song, Weixin Wang, Chiwun Yang

The Deep Leakage from Gradient (DLG) attack has emerged as a prevalent and highly effective method for extracting sensitive training data by inspecting exchanged gradients. This approach poses a substantial threat to the privacy of individuals and organizations alike. This research presents a comprehensive analysis of the gradient leakage method when applied specifically to transformer-based models. Through meticulous examination, we showcase the capability to accurately recover data solely from gradients and rigorously investigate the conditions under which gradient attacks can be executed, providing compelling evidence. Furthermore, we reevaluate the approach of introducing additional noise on gradients as a protective measure against gradient attacks. To address this, we outline a theoretical proof that analyzes the associated privacy costs within the framework of differential privacy. Additionally, we affirm the convergence of the Stochastic Gradient Descent (SGD) algorithm under perturbed gradients. The primary objective of this study is to augment the understanding of gradient leakage attack and defense strategies while actively contributing to the development of privacy-preserving techniques specifically tailored for transformer-based models. By shedding light on the vulnerabilities and countermeasures associated with gradient leakage, this research aims to foster advancements in safeguarding sensitive data and upholding privacy in the context of transformer-based models.

📄 PDF Abstract BibTeX arXiv:2311.13624

Code (0)

등록된 구현이 없습니다.

Tasks

Privacy Preserving

Similar Papers 제목 키워드 기반

DeepDefense: Layer-Wise Gradient-Feature Alignment for Building Robust Neural Networks

2025-11-13 · Ci Lin, Tet Yeap, Iluju Kiringa, Biwei Zhang arxiv

Deep neural networks are known to be vulnerable to adversarial perturbations, which are small and carefully crafted inputs that lead to incorrect predictions. In this paper, we propose DeepDefense, a novel defense framew…

Adversarial Robustness

Defense Against Adversarial Attacks on No-Reference Image Quality Models with Gradient Norm Regularization

2024-03-18 · CVPR 2024 1 · Yujia Liu, Chenxi Yang, Dingquan Li, Jianhao Ding 외

The task of No-Reference Image Quality Assessment (NR-IQA) is to estimate the quality score of an input image without additional information. NR-IQA models play a crucial role in the media industry, aiding in performance…

Adversarial RobustnessImage Quality AssessmentNo-Reference Image Quality Assessment

Black-box Gradient Attack on Graph Neural Networks: Deeper Insights in Graph-based Attack and Defense

2021-04-30 · Haoxi Zhan, Xiaobing Pei

Graph Neural Networks (GNNs) have received significant attention due to their state-of-the-art performance on various graph representation learning tasks. However, recent studies reveal that GNNs are vulnerable to advers…

Graph Representation LearningRepresentation Learning

TASER: Task-Aware Spectral Energy Refine for Backdoor Suppression in UAV Swarms Decentralized Federated Learning

2026-03-10 · Sizhe Huang, Shujie Yang arxiv

As backdoor attacks in UAV-based decentralized federated learning (DFL) grow increasingly stealthy and sophisticated, existing defenses have likewise escalated in complexity. Yet these defenses, which rely heavily on out…

Federated LearningOutlier Detection

Memory Efficient Full-gradient Attacks (MEFA) Framework for Adversarial Defense Evaluations

2026-05-07 · Yuan Du, Mitchel Hill, HanQin Cai arxiv

This work studies the robust evaluation of iterative stochastic purification defenses under white-box adversarial attacks. Our key technical insight is that gradient checkpointing makes exact end-to-end gradient computat…

Adversarial Defense