arXiv:2508.19819cs.CRcs.AI2025-08被引 2

实测发现,现代联邦学习中梯度反演难复现高保真图像。

Practical Feasibility of Gradient Inversion Attacks in Federated Learning

  • 在真实训练流程中测试梯度反演攻击可行性
  • 现代优化模型基本能抵御有效图像重建
  • 提醒警惕实验室理想条件与实际部署的差异

梯度反演攻击常被视为联邦学习中的严重隐私威胁,近期研究在理想实验条件下报告了越来越强的重建效果。然而,在实际部署的高性能系统中,此类攻击是否可行仍不明确。本文针对基于图像的联邦学习,系统评估了多种数据集和任务(包括图像分类与目标检测)下的梯度反演可行性,使用当代分辨率下的标准视觉架构。结果表明,尽管在某些遗留或过渡性设计下,梯度反演仍可能实现,但现代性能优化模型普遍能有效抵抗有意义的视觉重建。我们进一步证明,许多成功案例依赖于上界设置,如推理模式运行或架构简化,这些均不反映真实训练流程。综上,在诚实但好奇的服务器假设下,通过梯度反演实现高保真图像重建并非生产优化联邦学习系统的重大隐私风险,且实际风险评估必须严格区分诊断性攻击设置与真实部署场景。

原文摘要 · Abstract (English)

Gradient inversion attacks are often presented as a serious privacy threat in federated learning, with recent work reporting increasingly strong reconstructions under favorable experimental settings. However, it remains unclear whether such attacks are feasible in modern, performance-optimized systems deployed in practice. In this work, we evaluate the practical feasibility of gradient inversion for image-based federated learning. We conduct a systematic study across multiple datasets and tasks, including image classification and object detection, using canonical vision architectures at contemporary resolutions. Our results show that while gradient inversion remains possible for certain legacy or transitional designs under highly restrictive assumptions, modern, performance-optimized models consistently resist meaningful reconstruction visually. We further demonstrate that many reported successes rely on upper-bound settings, such as inference mode operation or architectural simplifications which do not reflect realistic training pipelines. Taken together, our findings indicate that, under an honest-but-curious server assumption, high-fidelity image reconstruction via gradient inversion does not constitute a critical privacy risk in production-optimized federated learning systems, and that practical risk assessments must carefully distinguish diagnostic attack settings from real-world deployments.

联邦学习隐私安全梯度反演

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。