Understanding Deep Gradient Leakage via Inversion Influence Functions

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Zhang, Haobo, Hong, Junyuan, Deng, Yuyang, Mahdavi, Mehrdad, Zhou, Jiayu
Format: Preprint
Publié: 2023
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866913189287952384
author Zhang, Haobo
Hong, Junyuan
Deng, Yuyang
Mahdavi, Mehrdad
Zhou, Jiayu
author_facet Zhang, Haobo
Hong, Junyuan
Deng, Yuyang
Mahdavi, Mehrdad
Zhou, Jiayu
contents Deep Gradient Leakage (DGL) is a highly effective attack that recovers private training images from gradient vectors. This attack casts significant privacy challenges on distributed learning from clients with sensitive data, where clients are required to share gradients. Defending against such attacks requires but lacks an understanding of when and how privacy leakage happens, mostly because of the black-box nature of deep networks. In this paper, we propose a novel Inversion Influence Function (I$^2$F) that establishes a closed-form connection between the recovered images and the private gradients by implicitly solving the DGL problem. Compared to directly solving DGL, I$^2$F is scalable for analyzing deep networks, requiring only oracle access to gradients and Jacobian-vector products. We empirically demonstrate that I$^2$F effectively approximated the DGL generally on different model architectures, datasets, modalities, attack implementations, and perturbation-based defenses. With this novel tool, we provide insights into effective gradient perturbation directions, the unfairness of privacy protection, and privacy-preferred model initialization. Our codes are provided in https://github.com/illidanlab/inversion-influence-function.
format Preprint
id arxiv_https___arxiv_org_abs_2309_13016
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Understanding Deep Gradient Leakage via Inversion Influence Functions
Zhang, Haobo
Hong, Junyuan
Deng, Yuyang
Mahdavi, Mehrdad
Zhou, Jiayu
Machine Learning
Cryptography and Security
Deep Gradient Leakage (DGL) is a highly effective attack that recovers private training images from gradient vectors. This attack casts significant privacy challenges on distributed learning from clients with sensitive data, where clients are required to share gradients. Defending against such attacks requires but lacks an understanding of when and how privacy leakage happens, mostly because of the black-box nature of deep networks. In this paper, we propose a novel Inversion Influence Function (I$^2$F) that establishes a closed-form connection between the recovered images and the private gradients by implicitly solving the DGL problem. Compared to directly solving DGL, I$^2$F is scalable for analyzing deep networks, requiring only oracle access to gradients and Jacobian-vector products. We empirically demonstrate that I$^2$F effectively approximated the DGL generally on different model architectures, datasets, modalities, attack implementations, and perturbation-based defenses. With this novel tool, we provide insights into effective gradient perturbation directions, the unfairness of privacy protection, and privacy-preferred model initialization. Our codes are provided in https://github.com/illidanlab/inversion-influence-function.
title Understanding Deep Gradient Leakage via Inversion Influence Functions
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2309.13016