paper-with-me

홈 › Papers

AFGI: Towards Accurate and Fast-convergent Gradient Inversion Attack in Federated Learning

2024-03-13 · Can Liu, Jin Wang, and Yipeng Zhou, Yachao Yuan, Quanzheng Sheng, Kejie Lu

Federated learning (FL) empowers privacypreservation in model training by only exposing users' model gradients. Yet, FL users are susceptible to gradient inversion attacks (GIAs) which can reconstruct ground-truth training data such as images based on model gradients. However, reconstructing high-resolution images by existing GIAs faces two challenges: inferior accuracy and slow-convergence, especially when duplicating labels exist in the training batch. To address these challenges, we present an Accurate and Fast-convergent Gradient Inversion attack algorithm, called AFGI, with two components: Label Recovery Block (LRB) which can accurately restore duplicating labels of private images based on exposed gradients; VME Regularization Term, which includes the total variance of reconstructed images, the discrepancy between three-channel means and edges, between values from exposed gradients and reconstructed images, respectively. The AFGI can be regarded as a white-box attack strategy to reconstruct images by leveraging labels recovered by LRB. In particular, AFGI is efficient that accurately reconstruct ground-truth images when users' training batch size is up to 48. Our experimental results manifest that AFGI can diminish 85% time costs while achieving superb inversion quality in the ImageNet dataset. At last, our study unveils the shortcomings of FL in privacy-preservation, prompting the development of more advanced countermeasure strategies.

📄 PDF Abstract BibTeX arXiv:2403.08383

Code (1)

Koukyosyumei/AIJack 공식 구현 pytorch

Tasks

Edge DetectionFederated Learning

Methods 이 논문이 사용한 방법론

Convolution A convolution is a type of matrix operation, consisting of a kernel, a small matrix of weights, that slides over input data performing element-wise multiplication with the…

Similar Papers 제목 키워드 기반

Surrogate Model Extension (SME): A Fast and Accurate Weight Update Attack on Federated Learning

2023-05-31 · Junyi Zhu, Ruicong Yao, Matthew B. Blaschko

In Federated Learning (FL) and many other distributed training frameworks, collaborators can hold their private data locally and only share the network weights trained with the local data after multiple iterations. Gradi…

Federated Learning

Differentially Private Generative Adversarial Networks with Model Inversion

2022-01-10 · Dongjie Chen, Sen-ching Samson Cheung, Chen-Nee Chuah, Sally Ozonoff

To protect sensitive data in training a Generative Adversarial Network (GAN), the standard approach is to use differentially private (DP) stochastic gradient descent method in which controlled noise is added to the gradi…

Generative Adversarial Networkmodel

Scaling SNNs Trained Using Equilibrium Propagation to Convolutional Architectures

2024-05-04 · Jiaqi Lin, Malyaban Bal, Abhronil Sengupta

Equilibrium Propagation (EP) is a biologically plausible local learning algorithm initially developed for convergent recurrent neural networks (RNNs), where weight updates rely solely on the connecting neuron states acro…

FireFlow: Fast Inversion of Rectified Flow for Image Semantic Editing

2024-12-10 · Yingying Deng, Xiangyu He, Changwang Mei, Peisong Wang 외

Though Rectified Flows (ReFlows) with distillation offers a promising way for fast sampling, its fast inversion transforms images back to structured noise for recovery and following editing remains unsolved. This paper i…

Text-based Image Editing

Gradient-free Decoder Inversion in Latent Diffusion Models

2024-09-27 · Seongmin Hong, Suh Yoon Jeon, Kyeonghyun Lee, Ernest K. Ryu 외

In latent diffusion models (LDMs), denoising diffusion process efficiently takes place on latent space whose dimension is lower than that of pixel space. Decoder is typically used to transform the representation in laten…

DecoderDenoisingGPUScheduling