CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Kaiyuan, Cheng, Siyuan, Shen, Guangyu, Ribeiro, Bruno, An, Shengwei, Chen, Pin-Yu, Zhang, Xiangyu, Li, Ninghui
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929687915134976
author Zhang, Kaiyuan
Cheng, Siyuan
Shen, Guangyu
Ribeiro, Bruno
An, Shengwei
Chen, Pin-Yu
Zhang, Xiangyu
Li, Ninghui
author_facet Zhang, Kaiyuan
Cheng, Siyuan
Shen, Guangyu
Ribeiro, Bruno
An, Shengwei
Chen, Pin-Yu
Zhang, Xiangyu
Li, Ninghui
contents Federated learning collaboratively trains a neural network on a global server, where each local client receives the current global model weights and sends back parameter updates (gradients) based on its local private data. The process of sending these model updates may leak client's private data information. Existing gradient inversion attacks can exploit this vulnerability to recover private training instances from a client's gradient vectors. Recently, researchers have proposed advanced gradient inversion techniques that existing defenses struggle to handle effectively. In this work, we present a novel defense tailored for large neural network models. Our defense capitalizes on the high dimensionality of the model parameters to perturb gradients within a subspace orthogonal to the original gradient. By leveraging cold posteriors over orthogonal subspaces, our defense implements a refined gradient update mechanism. This enables the selection of an optimal gradient that not only safeguards against gradient inversion attacks but also maintains model utility. We conduct comprehensive experiments across three different datasets and evaluate our defense against various state-of-the-art attacks and defenses. Code is available at https://censor-gradient.github.io.
format Preprint
id arxiv_https___arxiv_org_abs_2501_15718
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling
Zhang, Kaiyuan
Cheng, Siyuan
Shen, Guangyu
Ribeiro, Bruno
An, Shengwei
Chen, Pin-Yu
Zhang, Xiangyu
Li, Ninghui
Machine Learning
Cryptography and Security
Federated learning collaboratively trains a neural network on a global server, where each local client receives the current global model weights and sends back parameter updates (gradients) based on its local private data. The process of sending these model updates may leak client's private data information. Existing gradient inversion attacks can exploit this vulnerability to recover private training instances from a client's gradient vectors. Recently, researchers have proposed advanced gradient inversion techniques that existing defenses struggle to handle effectively. In this work, we present a novel defense tailored for large neural network models. Our defense capitalizes on the high dimensionality of the model parameters to perturb gradients within a subspace orthogonal to the original gradient. By leveraging cold posteriors over orthogonal subspaces, our defense implements a refined gradient update mechanism. This enables the selection of an optimal gradient that not only safeguards against gradient inversion attacks but also maintains model utility. We conduct comprehensive experiments across three different datasets and evaluate our defense against various state-of-the-art attacks and defenses. Code is available at https://censor-gradient.github.io.
title CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2501.15718