arXiv:2603.17623cs.LGcs.CR2026-03

无需修改模型结构,即可高保真还原联邦学习中的训练数据。

ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning through Activation Recovery

  • 将激活恢复建模为带噪稀疏恢复问题,用广义Lasso求解。
  • 在大批次下重建准确率显著优于已有方法,支持多样本可扩展重构。
  • 首次提供理论保证,揭示中间激活是联邦学习中被低估的隐私风险。

联邦学习通过共享模型更新而非原始数据实现协作训练,旨在保护用户隐私。然而,近期研究发现这些共享更新可能通过梯度反演攻击(GIAs)泄露敏感训练数据。其中,主动式GIAs尤其强大,可在大批次下高保真重构单个样本。但现有方法常需架构修改,限制了实际应用。本文提出激活恢复稀疏反演(ARES)攻击,一种无需架构修改即可从大批次中重构训练样本的主动式梯度反演攻击。我们将其建模为带噪稀疏恢复问题,并使用广义最小绝对收缩选择算子(Lasso)求解。为实现多样本恢复,ARES引入印迹法分离激活,支持可扩展的逐样本重构。进一步建立了预期重建率并推导出重构误差上界,提供了理论保障。在CNN和MLP上的大量实验表明,ARES在多种数据集上均实现高保真重建,显著优于先前GIAs在大批次和真实联邦学习场景下的表现。结果强调,中间激活在联邦学习中构成严重且被低估的隐私风险,亟需更强防御措施。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative model training by sharing model updates instead of raw data, aiming to protect user privacy. However, recent studies reveal that these shared updates can inadvertently leak sensitive training data through gradient inversion attacks (GIAs). Among them, active GIAs are particularly powerful, enabling high-fidelity reconstruction of individual samples even under large batch sizes. Nevertheless, existing approaches often require architectural modifications, which limit their practical applicability. In this work, we bridge this gap by introducing the Activation REcovery via Sparse inversion (ARES) attack, an active GIA designed to reconstruct training samples from large training batches without requiring architectural modifications. Specifically, we formulate the recovery problem as a noisy sparse recovery task and solve it using the generalized Least Absolute Shrinkage and Selection Operator (Lasso). To extend the attack to multi-sample recovery, ARES incorporates the imprint method to disentangle activations, enabling scalable per-sample reconstruction. We further establish the expected recovery rate and derive an upper bound on the reconstruction error, providing theoretical guarantees for the ARES attack. Extensive experiments on CNNs and MLPs demonstrate that ARES achieves high-fidelity reconstruction across diverse datasets, significantly outperforming prior GIAs under large batch sizes and realistic FL settings. Our results highlight that intermediate activations pose a serious and underestimated privacy risk in FL, underscoring the urgent need for stronger defenses.

联邦学习隐私攻击梯度反演激活恢复

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。