AIセキュリティポータル K Program
Dealing Doubt: Unveiling Threat Models in Gradient Inversion Attacks under Federated Learning, A Survey and Taxonomy
Share
Abstract
Federated Learning (FL) has emerged as a leading paradigm for decentralized, privacy preserving machine learning training. However, recent research on gradient inversion attacks (GIAs) have shown that gradient updates in FL can leak information on private training samples. While existing surveys on GIAs have focused on the honest-but-curious server threat model, there is a dearth of research categorizing attacks under the realistic and far more privacy-infringing cases of malicious servers and clients. In this paper, we present a survey and novel taxonomy of GIAs that emphasize FL threat models, particularly that of malicious servers and clients. We first formally define GIAs and contrast conventional attacks with the malicious attacker. We then summarize existing honest-but-curious attack strategies, corresponding defenses, and evaluation metrics. Critically, we dive into attacks with malicious servers and clients to highlight how they break existing FL defenses, focusing specifically on reconstruction methods, target model architectures, target data, and evaluation metrics. Lastly, we discuss open problems and future research directions.
Reconstructing Individual Data Points in Federated Learning Hardened with Differential Privacy and Secure Aggregation
Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, Nicolas Papernot
Published: 1.10.2023
When the Curious Abandon Honesty: Federated Learning Is Not Private
Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, Nicolas Papernot
Published: 12.6.2021
Practical Secure Aggregation for Federated Learning on User-Held Data
Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H. Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, Karn Seth
Published: 11.15.2016
Towards federated learning at scale: System design
K. Bonawitz
Published: 2019
Broadening the scope of differential privacy using metrics
Konstantinos Chatzikoklakis, Miguel E Andrés, Nicolás Emilio Bordenabe, Catuscia Palamidessi
Published: 2013
Understanding Training-Data Leakage from Gradients in Neural Networks for Image Classification
Cangxiong Chen, Neill D. F. Campbell
Published: 11.19.2021
An Overview of Federated Deep Learning Privacy Attacks and Defensive Strategies
David Enthoven, Zaid Al-Ars
Published: 4.1.2020
Gifd: A generative gradient inversion method with feature domain optimization
Hao Fang, Bin Chen, Xuan Wang, Zhi Wang, Shu-Tao Xia
Published: 2023
Shuffled model of differential privacy in federated learning
A. M. Girgis, D. Data, S. N. Diggavi, P. Kairouz, A. T. Suresh
Published: 2021
Recovering private text in federated learning of language models
Samyak Gupta, Yangsibo Huang, Zexuan Zhong, Tianyu Gao, Kai Li, Danqi Chen
Published: 2022
Federated learning with compression: Unified analysis and sharp guarantees
Farzin Haddadpour, Mohammad Mahdi Kamani, Aryan Mokhtari, Mehrdad Mahdavi
Published: 2020
Do gradient inversion attacks make federated learning unsafe?
Ali Hatamizadeh, Hongxu Yin, Pavlo Molchanov, Andriy Myronenko, Wenqi Li, Prerna Dogra, Andrew Feng, Mona G Flores, Jan Kautz, Daguang Xu
Published: 2023
Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning
Briland Hitaj, Giuseppe Ateniese, Fernando Perez-Cruz
Published: 2.24.2017
How to make private distributed cardinality estimation practical, and get differential privacy for free
Changhui Hu, Jin Li, Zheli Liu, Xiaojie Guo, Yu Wei, Xuan Guang, Grigorios Loukides, Changyu Dong
Published: 2021
Evaluating gradient inversion attacks and defenses in federated learning
Yangsibo Huang, Samyak Gupta, Zhao Song, Kai Li, Sanjeev Arora
Published: 2021
InstaHide: Instance-hiding Schemes for Private Distributed Learning
Yangsibo Huang, Zhao Song, Kai Li, Sanjeev Arora
Published: 10.6.2020
Gradient inversion with generative image prior
Jinwoo Jeon, Kangwook Lee, Sewoong Oh, Jungseul Ok
Published: 2021
Cafe: Catastrophic data leakage in federated learning
X. Jin, R. Du, P.-Y. Chen, T. Chen
Published: 2021
Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning using Independent Component Analysis
Sanjay Kariyappa, Chuan Guo, Kiwan Maeng, Wenjie Xiong, G. Edward Suh, Moinuddin K Qureshi, Hsien-Hsin S. Lee
Published: 9.13.2022
Pufferfish: A framework for mathematical privacy definitions
Daniel Kifer, Ashwin Machanavajjhala
Published: 2014
Gradient disaggregation: Breaking privacy in federated learning by reconstructing the user participant matrix
Maximilian Lam, Gu-Yeon Wei, David Brooks, Vijay Janapa Reddi, Michael Mitzenmacher
Published: 2021
An experimental study of byzantine-robust aggregation schemes in federated learning
S. Li, E. C.-H. Ngai, T. Voigt
Published: 2023
April: Finding the achilles’ heel on privacy for vision transformers
Jiahao Lu, Xi Sheryl Zhang, Tianli Zhao, Xiangyu He, Jian Cheng
Published: 2021
Communication-Efficient Learning of Deep Networks from Decentralized Data
H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, Blaise Agüera y Arcas
Published: 2.18.2016
Layer-wise characterization of latent information leakage in federated learning
Fan Mo, Anastasia Borovykh, Mohammad Malekzadeh, Hamed Haddadi, Soteris Demetriou
Published: 2021
Absolute variation distance: an inversion attack evaluation metric for federated learning
Georgios Papadopoulos, Yash Satsangi, Shaltiel Eloul, Marco Pistoia
Published: 2023
Eluding secure aggregation in federated learning via model inconsistency
Dario Pasquini, Danilo Francati, Giuseppe Ateniese
Published: 2022
Posthoc privacy guarantees for collaborative inference with modified propose-test-release
Abhishek Singh, Praneeth Vepakomma, Vivek Sharma, Ramesh Raskar
Published: 2023
Federated learning attacks revisited: A critical discussion of gaps, assumptions, and evaluation setups
Aidmar Wainakh, Ephraim Zimmer, Sandeep Subedi, Jens Keim, Tim Grube, Shankar Karuppayah, Alejandro Sanchez Guinea, Max Müllerhäuser
Published: 2022
Image quality assessment: from error visibility to structural similarity
Z. Wang, A. C. Bovik, H. R. Sheikh, E. P. Simoncelli
Published: 2004
A Framework for Evaluating Gradient Leakage Attacks in Federated Learning
Wenqi Wei, Ling Liu, Margaret Loper, Ka-Ho Chow, Mehmet Emre Gursoy, Stacey Truex, Yanzhao Wu
Published: 4.22.2020
Learning to invert: Simple adaptive attacks for gradient inversion in federated learning
Ruihan Wu, Xiangyu Chen, Chuan Guo, Kilian Q. Weinberger
Published: 2023
A theory of usable information under computational constraints
Yilun Xu, Shengjia Zhao, Jiaming Song, Russell Stewart, Stefano Ermon
Published: 2020
See through gradients: Image batch recovery via gradinversion
Hongxu Yin, Arun Mallya, Arash Vahdat, Jose M Alvarez, Jan Kautz, Pavlo Molchanov
Published: 2021
Gradient Obfuscation Gives a False Sense of Security in Federated Learning
Kai Yue, Richeng Jin, Chau-Wai Wong, Dror Baron, Huaiyu Dai
Published: 6.8.2022
R-gap: Recursive gradient attack on privacy
Junyi Zhu, Matthew Blaschko
Published: 2021
Share