arXiv:2511.10502cs.CRcs.AI2025-11

提出轻量检测方法,识别联邦学习中恶意服务器的梯度反演攻击

On the Detectability of Active Gradient Inversion Attacks in Federated Learning

  • 基于权重结构异常和损失梯度动态,设计客户端侧检测机制
  • 在多种配置下验证,可有效识别四种前沿主动梯度反演攻击
  • 无需修改训练协议,适合部署于资源受限的客户端

联邦学习(FL)虽能保护客户端数据隐私,但训练过程中交换的梯度仍可能遭受梯度反演攻击(GIA),导致本地数据被重建。此类攻击可由被动或主动服务器发起;其中主动攻击通过操纵全局模型来辅助数据重构,更具威胁性。尽管早期主动攻击易被检测,近年出现的新攻击宣称具备更高隐蔽性。本文首次系统评估了四种前沿主动GIA,提出基于统计异常权重结构与异常损失/梯度动态的轻量级客户端检测方法。大量实验表明,该方法无需修改联邦学习训练流程,即可有效检测主动攻击。

原文摘要 · Abstract (English)

One of the key advantages of Federated Learning (FL) is its ability to collaboratively train a Machine Learning (ML) model while keeping clients' data on-site. However, this can create a false sense of security. Despite not sharing private data increases the overall privacy, prior studies have shown that gradients exchanged during the FL training remain vulnerable to Gradient Inversion Attacks (GIAs). These attacks allow reconstructing the clients' local data, breaking the privacy promise of FL. GIAs can be launched by either a passive or an active server. In the latter case, a malicious server manipulates the global model to facilitate data reconstruction. While effective, earlier attacks falling under this category have been demonstrated to be detectable by clients, limiting their real-world applicability. Recently, novel active GIAs have emerged, claiming to be far stealthier than previous approaches. This work provides the first comprehensive analysis of these claims, investigating four state-of-the-art GIAs. We propose novel lightweight client-side detection techniques, based on statistically improbable weight structures and anomalous loss and gradient dynamics. Extensive evaluation across several configurations demonstrates that our methods enable clients to effectively detect active GIAs without any modifications to the FL training protocol.

联邦学习隐私安全梯度反演检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。