arXiv:2505.20026cs.LGcs.AI2025-05被引 1

用生成模型从泄露梯度中还原训练数据,效果优于现有方法。

Gradient Inversion Transcript: Leveraging Robust Generative Priors to Reconstruct Training Data from Gradient Leakage

  • 设计匹配目标模型结构的生成攻击模型,实现高效重建。
  • 在多数据集上表现更优,对梯度误差、参数差异等有强鲁棒性。
  • 可作为先验加速其他方法,适合隐私安全研究者使用。

我们提出 Gradient Inversion Transcript (GIT),一种新型生成式方法,用于从泄露的梯度中重构训练数据。GIT采用根据理论分析定制架构的生成攻击模型,离线训练后仅需泄露梯度即可高效部署,适用于多种分布式学习环境。当作为其他基于迭代优化方法的先验时,GIT不仅加速收敛,还提升整体重建质量。GIT在多个数据集上持续优于现有方法,在梯度不准确、数据分布偏移及模型参数差异等挑战性条件下表现出强鲁棒性。

原文摘要 · Abstract (English)

We propose Gradient Inversion Transcript (GIT), a novel generative approach for reconstructing training data from leaked gradients. GIT employs a generative attack model, whose architecture is tailored to align with the structure of the leaked model based on theoretical analysis. Once trained offline, GIT can be deployed efficiently and only relies on the leaked gradients to reconstruct the input data, rendering it applicable under various distributed learning environments. When used as a prior for other iterative optimization-based methods, GIT not only accelerates convergence but also enhances the overall reconstruction quality. GIT consistently outperforms existing methods across multiple datasets and demonstrates strong robustness under challenging conditions, including inaccurate gradients, data distribution shifts and discrepancies in model parameters.

梯度泄露生成模型数据重建隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。