arXiv:2507.09602cs.LGcs.AI2025-07

攻击联邦遗忘中的梯度差异,重建被删除的数据。

DRAGD: A Federated Unlearning Data Reconstruction Attack Based on Gradient Differences

  • 利用遗忘前后梯度差重构被删除数据
  • 在人脸等复杂数据上重建精度显著提升
  • 揭示联邦遗忘的隐私漏洞,适合安全研究者

联邦学习在保护数据隐私的同时实现协同建模,但联邦遗忘机制(用于让客户端从全局模型中移除其数据)带来了新的隐私风险。具体而言,遗忘过程中梯度交换可能泄露被删除数据的敏感信息。本文提出DRAGD,一种基于遗忘前后梯度差异的新型数据重建攻击方法;并引入增强版DRAGDP,利用公开先验数据提升复杂数据(如人脸图像)的重建准确率。在多个数据集上的实验表明,DRAGD与DRAGDP显著优于现有方法。本工作揭示了联邦遗忘中的关键隐私缺陷,并为实际应用中提升系统安全性提供了可行方案。

原文摘要 · Abstract (English)

Federated learning enables collaborative machine learning while preserving data privacy. However, the rise of federated unlearning, designed to allow clients to erase their data from the global model, introduces new privacy concerns. Specifically, the gradient exchanges during the unlearning process can leak sensitive information about deleted data. In this paper, we introduce DRAGD, a novel attack that exploits gradient discrepancies before and after unlearning to reconstruct forgotten data. We also present DRAGDP, an enhanced version of DRAGD that leverages publicly available prior data to improve reconstruction accuracy, particularly for complex datasets like facial images. Extensive experiments across multiple datasets demonstrate that DRAGD and DRAGDP significantly outperform existing methods in data reconstruction.Our work highlights a critical privacy vulnerability in federated unlearning and offers a practical solution, advancing the security of federated unlearning systems in real-world applications.

联邦学习数据遗忘隐私攻击梯度泄漏

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。