SPEAR:Exact Gradient Inversion of Batches in Federated Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Dimitrov, Dimitar I., Baader, Maximilian, Müller, Mark Niklas, Vechev, Martin
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866929620220116992
author Dimitrov, Dimitar I.
Baader, Maximilian
Müller, Mark Niklas
Vechev, Martin
author_facet Dimitrov, Dimitar I.
Baader, Maximilian
Müller, Mark Niklas
Vechev, Martin
contents Federated learning is a framework for collaborative machine learning where clients only share gradient updates and not their private data with a server. However, it was recently shown that gradient inversion attacks can reconstruct this data from the shared gradients. In the important honest-but-curious setting, existing attacks enable exact reconstruction only for batch size of $b=1$, with larger batches permitting only approximate reconstruction. In this work, we propose SPEAR, the first algorithm reconstructing whole batches with $b >1$ exactly. SPEAR combines insights into the explicit low-rank structure of gradients with a sampling-based algorithm. Crucially, we leverage ReLU-induced gradient sparsity to precisely filter out large numbers of incorrect samples, making a final reconstruction step tractable. We provide an efficient GPU implementation for fully connected networks and show that it recovers high-dimensional ImageNet inputs in batches of up to $b \lesssim 25$ exactly while scaling to large networks. Finally, we show theoretically that much larger batches can be reconstructed with high probability given exponential time.
format Preprint
id arxiv_https___arxiv_org_abs_2403_03945
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle SPEAR:Exact Gradient Inversion of Batches in Federated Learning
Dimitrov, Dimitar I.
Baader, Maximilian
Müller, Mark Niklas
Vechev, Martin
Machine Learning
Cryptography and Security
Distributed, Parallel, and Cluster Computing
I.2.11
Federated learning is a framework for collaborative machine learning where clients only share gradient updates and not their private data with a server. However, it was recently shown that gradient inversion attacks can reconstruct this data from the shared gradients. In the important honest-but-curious setting, existing attacks enable exact reconstruction only for batch size of $b=1$, with larger batches permitting only approximate reconstruction. In this work, we propose SPEAR, the first algorithm reconstructing whole batches with $b >1$ exactly. SPEAR combines insights into the explicit low-rank structure of gradients with a sampling-based algorithm. Crucially, we leverage ReLU-induced gradient sparsity to precisely filter out large numbers of incorrect samples, making a final reconstruction step tractable. We provide an efficient GPU implementation for fully connected networks and show that it recovers high-dimensional ImageNet inputs in batches of up to $b \lesssim 25$ exactly while scaling to large networks. Finally, we show theoretically that much larger batches can be reconstructed with high probability given exponential time.
title SPEAR:Exact Gradient Inversion of Batches in Federated Learning
topic Machine Learning
Cryptography and Security
Distributed, Parallel, and Cluster Computing
I.2.11
url https://arxiv.org/abs/2403.03945