用生成式流匹配提升联邦学习数据泄露攻击精度
Deep Leakage with Generative Flow Matching Denoiser
- 引入流匹配生成先验,引导重建更逼真图像
- 在多个数据集上超越现有攻击方法,保持稳定性能
- 适用于对抗噪声、剪裁等常见防御手段,适合安全研究者参考
联邦学习(FL)虽能实现去中心化模型训练,但仍面临深度数据泄露(DL)攻击风险,即通过共享的模型更新重构私有客户端数据。已有方法常存在不稳定性、保真度低或在真实FL场景下鲁棒性差的问题。本文提出一种新型DL攻击,将生成式流匹配(Flow Matching, FM)先验融入重建过程,利用基础流匹配模型所表征的真实图像分布,指导优化以提升重建质量,无需了解私有数据。在多个数据集和目标模型上的大量实验表明,该方法在像素级、感知和特征层面的相似性指标上均持续优于现有最先进攻击方法。关键的是,该方法在不同训练轮次、更大客户端批量及常见防御策略(如噪声注入、梯度剪裁、稀疏化)下仍保持有效性。研究结果提示需开发能应对强大生成先验的新型防御机制。
原文摘要 · Abstract (English)
Federated Learning (FL) has emerged as a powerful paradigm for decentralized model training, yet it remains vulnerable to deep leakage (DL) attacks that reconstruct private client data from shared model updates. While prior DL methods have demonstrated varying levels of success, they often suffer from instability, limited fidelity, or poor robustness under realistic FL settings. We introduce a new DL attack that integrates a generative Flow Matching (FM) prior into the reconstruction process. By guiding optimization toward the distribution of realistic images (represented by a flow matching foundation model), our method enhances reconstruction fidelity without requiring knowledge of the private data. Extensive experiments on multiple datasets and target models demonstrate that our approach consistently outperforms state-of-the-art attacks across pixel-level, perceptual, and feature-based similarity metrics. Crucially, the method remains effective across different training epochs, larger client batch sizes, and under common defenses such as noise injection, clipping, and sparsification. Our findings call for the development of new defense strategies that explicitly account for adversaries equipped with powerful generative priors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。