Optimal Defenses Against Gradient Reconstruction Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Chen, Yuxiao, Gürsoy, Gamze, Lei, Qi
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910686691459072
author Chen, Yuxiao
Gürsoy, Gamze
Lei, Qi
author_facet Chen, Yuxiao
Gürsoy, Gamze
Lei, Qi
contents Federated Learning (FL) is designed to prevent data leakage through collaborative model training without centralized data storage. However, it remains vulnerable to gradient reconstruction attacks that recover original training data from shared gradients. To optimize the trade-off between data leakage and utility loss, we first derive a theoretical lower bound of reconstruction error (among all attackers) for the two standard methods: adding noise, and gradient pruning. We then customize these two defenses to be parameter- and model-specific and achieve the optimal trade-off between our obtained reconstruction lower bound and model utility. Experimental results validate that our methods outperform Gradient Noise and Gradient Pruning by protecting the training data better while also achieving better utility.
format Preprint
id arxiv_https___arxiv_org_abs_2411_03746
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Optimal Defenses Against Gradient Reconstruction Attacks
Chen, Yuxiao
Gürsoy, Gamze
Lei, Qi
Machine Learning
Artificial Intelligence
Cryptography and Security
Federated Learning (FL) is designed to prevent data leakage through collaborative model training without centralized data storage. However, it remains vulnerable to gradient reconstruction attacks that recover original training data from shared gradients. To optimize the trade-off between data leakage and utility loss, we first derive a theoretical lower bound of reconstruction error (among all attackers) for the two standard methods: adding noise, and gradient pruning. We then customize these two defenses to be parameter- and model-specific and achieve the optimal trade-off between our obtained reconstruction lower bound and model utility. Experimental results validate that our methods outperform Gradient Noise and Gradient Pruning by protecting the training data better while also achieving better utility.
title Optimal Defenses Against Gradient Reconstruction Attacks
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2411.03746