arXiv:2509.22082cs.LGcs.CR2025-09被引 2

提出新方法破解联邦学习多步梯度反演,揭示隐私泄露风险

Trajectory-Aware Information Matching for Multi-Step Gradient Inversion in Federated Learning

  • 构建可学习的非线性轨迹模型,匹配多步更新中的隐藏状态
  • 在多种设置下重建精度超越现有方法,尤其在医疗图像上表现优异
  • 适合关注联邦学习隐私安全的研究者和系统设计者

联邦学习可在不暴露原始客户端数据的情况下实现分布式信息共享与协同训练。然而,共享的梯度或模型更新仍可能包含敏感信息,使联邦学习易受梯度反演攻击。现有攻击大多基于简化更新观测,如单步梯度或终点匹配。在实际联邦平均(FedAvg)中,经过多轮本地训练后生成的是累积的、依赖轨迹的更新,而非单一模型状态下的梯度。为此,本文提出NL-SME,一种面向多步梯度反演的轨迹感知信息匹配方法。NL-SME通过可学习的非线性代理轨迹逼近隐藏的本地状态,并将轨迹级信息与校准后的梯度匹配相结合。对于被扰动的更新,还引入可观测更新可靠性感知策略,降低不可靠成分的影响。在多种多步FedAvg设置下的大量实验表明,NL-SME在重建质量和更新匹配准确率方面均优于当前最优基线。对自然图像与医学图像的额外评估,以及在融合更新观测和典型防御策略下的测试进一步表明,可观测的多步更新仍可能保留可重构信号。这些结果揭示了联邦信息共享中潜在的隐私泄露风险。代码已公开于 https://anonymous.4open.science/r/NL-SME-main/README.md。

原文摘要 · Abstract (English)

Federated learning enables distributed information sharing and collaborative model training without exposing raw client data. However, shared gradients or model updates may still contain sensitive information, making federated learning vulnerable to gradient inversion attacks. Most existing gradient inversion attacks rely on simplified update observations, such as single-step gradients or endpoint-based matching. In practical FL, however, FedAvg produces an accumulated trajectory-dependent update after multiple local steps, rather than a gradient computed at a single model state.To address this issue, we propose NL-SME, a trajectory-aware information matching method for multi-step gradient inversion. NL-SME constructs a learnable nonlinear surrogate trajectory to approximate hidden local states and integrates trajectory-level information with calibrated gradient matching. For perturbed updates, NL-SME can further use an observed-update reliability-aware strategy to reduce the influence of unreliable components. Extensive experiments under diverse multi-step FedAvg settings show that NL-SME outperforms state-of-the-art gradient inversion baselines in reconstruction quality and update-matching accuracy. Additional evaluations on natural and medical images, as well as under fused-update observations and representative defense strategies, further suggest that observable multi-step updates may still retain reconstruction signals. These results reveal potential privacy leakage risks in federated information sharing. Code is available at https://anonymous.4open.science/r/NL-SME-main/README.md.

联邦学习隐私安全梯度反演多步更新

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。