arXiv:2510.17621cs.CRcs.AI2025-10被引 2

用去噪模型提升联邦学习中的梯度反演攻击,让隐私泄露更严重。

GUIDE: Enhancing Gradient Inversion Attacks in Federated Learning with Denoising Models

  • 引入扩散模型作为去噪工具,优化梯度反演图像重建
  • 在多个场景下使重建图像感知相似度提升46%(DreamSim)
  • 可适配主流反演攻击方法,适合研究隐私安全的学者

联邦学习(FL)允许多个客户端在不共享原始数据的情况下协同训练机器学习模型,从而增强隐私保护。然而,客户端上传的模型更新仍可能泄露隐私。在诚实但好奇的威胁模型下,攻击者可通过基于优化的梯度反演攻击(GIAs)重构训练数据。现有方法通常生成噪声较大的近似图像,我们观察到通过专用去噪模型可显著提升重建质量。本文提出梯度更新反演去噪(GUIDE)方法,利用扩散模型作为去噪工具,改进联邦学习中的图像重建攻击。GUIDE可集成到依赖代理数据集的各类GIAs中,该假设在现有文献中广泛使用。我们在两种不同联邦算法、模型和数据集的攻击场景下全面评估了本方法。结果表明,GUIDE能无缝融合两种先进GIAs,显著提升多种指标下的重建质量,尤其在DreamSim度量下感知相似度最高提升46%。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative training of Machine Learning (ML) models across multiple clients while preserving their privacy. Rather than sharing raw data, federated clients transmit locally computed updates to train the global model. Although this paradigm should provide stronger privacy guarantees than centralized ML, client updates remain vulnerable to privacy leakage. Adversaries can exploit them to infer sensitive properties about the training data or even to reconstruct the original inputs via Gradient Inversion Attacks (GIAs). Under the honest-butcurious threat model, GIAs attempt to reconstruct training data by reversing intermediate updates using optimizationbased techniques. We observe that these approaches usually reconstruct noisy approximations of the original inputs, whose quality can be enhanced with specialized denoising models. This paper presents Gradient Update Inversion with DEnoising (GUIDE), a novel methodology that leverages diffusion models as denoising tools to improve image reconstruction attacks in FL. GUIDE can be integrated into any GIAs that exploits surrogate datasets, a widely adopted assumption in GIAs literature. We comprehensively evaluate our approach in two attack scenarios that use different FL algorithms, models, and datasets. Our results demonstrate that GUIDE integrates seamlessly with two state-ofthe- art GIAs, substantially improving reconstruction quality across multiple metrics. Specifically, GUIDE achieves up to 46% higher perceptual similarity, as measured by the DreamSim metric.

联邦学习隐私攻击去噪模型扩散模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。