Cutting Through Privacy: A Hyperplane-Based Data Reconstruction Attack in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Diana, Francesco, Nusser, André, Xu, Chuan, Neglia, Giovanni
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915480942411776
author Diana, Francesco
Nusser, André
Xu, Chuan
Neglia, Giovanni
author_facet Diana, Francesco
Nusser, André
Xu, Chuan
Neglia, Giovanni
contents Federated Learning (FL) enables collaborative training of machine learning models across distributed clients without sharing raw data, ostensibly preserving data privacy. Nevertheless, recent studies have revealed critical vulnerabilities in FL, showing that a malicious central server can manipulate model updates to reconstruct clients' private training data. Existing data reconstruction attacks have important limitations: they often rely on assumptions about the clients' data distribution or their efficiency significantly degrades when batch sizes exceed just a few tens of samples. In this work, we introduce a novel data reconstruction attack that overcomes these limitations. Our method leverages a new geometric perspective on fully connected layers to craft malicious model parameters, enabling the perfect recovery of arbitrarily large data batches in classification tasks without any prior knowledge of clients' data. Through extensive experiments on both image and tabular datasets, we demonstrate that our attack outperforms existing methods and achieves perfect reconstruction of data batches two orders of magnitude larger than the state of the art.
format Preprint
id arxiv_https___arxiv_org_abs_2505_10264
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Cutting Through Privacy: A Hyperplane-Based Data Reconstruction Attack in Federated Learning
Diana, Francesco
Nusser, André
Xu, Chuan
Neglia, Giovanni
Machine Learning
Artificial Intelligence
Cryptography and Security
Federated Learning (FL) enables collaborative training of machine learning models across distributed clients without sharing raw data, ostensibly preserving data privacy. Nevertheless, recent studies have revealed critical vulnerabilities in FL, showing that a malicious central server can manipulate model updates to reconstruct clients' private training data. Existing data reconstruction attacks have important limitations: they often rely on assumptions about the clients' data distribution or their efficiency significantly degrades when batch sizes exceed just a few tens of samples. In this work, we introduce a novel data reconstruction attack that overcomes these limitations. Our method leverages a new geometric perspective on fully connected layers to craft malicious model parameters, enabling the perfect recovery of arbitrarily large data batches in classification tasks without any prior knowledge of clients' data. Through extensive experiments on both image and tabular datasets, we demonstrate that our attack outperforms existing methods and achieves perfect reconstruction of data batches two orders of magnitude larger than the state of the art.
title Cutting Through Privacy: A Hyperplane-Based Data Reconstruction Attack in Federated Learning
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2505.10264