Enhancing Gradient Inversion Attacks in Federated Learning via Hierarchical Feature Optimization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Fang, Hao, Yu, Wenbo, Chen, Bin, Wang, Xuan, Xia, Shu-Tao, Liao, Qing, Xu, Ke
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917377662255104
author Fang, Hao
Yu, Wenbo
Chen, Bin
Wang, Xuan
Xia, Shu-Tao
Liao, Qing
Xu, Ke
author_facet Fang, Hao
Yu, Wenbo
Chen, Bin
Wang, Xuan
Xia, Shu-Tao
Liao, Qing
Xu, Ke
contents Federated Learning (FL) has emerged as a compelling paradigm for privacy-preserving distributed machine learning, allowing multiple clients to collaboratively train a global model by transmitting locally computed gradients to a central server without exposing their private data. Nonetheless, recent studies find that the gradients exchanged in the FL system are also vulnerable to privacy leakage, e.g., an attacker can invert shared gradients to reconstruct sensitive data by leveraging pre-trained generative adversarial networks (GAN) as prior knowledge. However, existing attacks simply perform gradient inversion in the latent space of the GAN model, which limits their expression ability and generalizability. To tackle these challenges, we propose \textbf{G}radient \textbf{I}nversion over \textbf{F}eature \textbf{D}omains (GIFD), which disassembles the GAN model and searches the hierarchical features of the intermediate layers. Instead of optimizing only over the initial latent code, we progressively change the optimized layer, from the initial latent space to intermediate layers closer to the output images. In addition, we design a regularizer to avoid unreal image generation by adding a small ${l_1}$ ball constraint to the searching range. We also extend GIFD to the out-of-distribution (OOD) setting, which weakens the assumption that the training sets of GANs and FL tasks obey the same data distribution. Furthermore, we consider the challenging OOD scenario of label inconsistency and propose a label mapping technique as an effective solution. Extensive experiments demonstrate that our method can achieve pixel-level reconstruction and outperform competitive baselines across a variety of FL scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2604_00955
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Enhancing Gradient Inversion Attacks in Federated Learning via Hierarchical Feature Optimization
Fang, Hao
Yu, Wenbo
Chen, Bin
Wang, Xuan
Xia, Shu-Tao
Liao, Qing
Xu, Ke
Computer Vision and Pattern Recognition
Federated Learning (FL) has emerged as a compelling paradigm for privacy-preserving distributed machine learning, allowing multiple clients to collaboratively train a global model by transmitting locally computed gradients to a central server without exposing their private data. Nonetheless, recent studies find that the gradients exchanged in the FL system are also vulnerable to privacy leakage, e.g., an attacker can invert shared gradients to reconstruct sensitive data by leveraging pre-trained generative adversarial networks (GAN) as prior knowledge. However, existing attacks simply perform gradient inversion in the latent space of the GAN model, which limits their expression ability and generalizability. To tackle these challenges, we propose \textbf{G}radient \textbf{I}nversion over \textbf{F}eature \textbf{D}omains (GIFD), which disassembles the GAN model and searches the hierarchical features of the intermediate layers. Instead of optimizing only over the initial latent code, we progressively change the optimized layer, from the initial latent space to intermediate layers closer to the output images. In addition, we design a regularizer to avoid unreal image generation by adding a small ${l_1}$ ball constraint to the searching range. We also extend GIFD to the out-of-distribution (OOD) setting, which weakens the assumption that the training sets of GANs and FL tasks obey the same data distribution. Furthermore, we consider the challenging OOD scenario of label inconsistency and propose a label mapping technique as an effective solution. Extensive experiments demonstrate that our method can achieve pixel-level reconstruction and outperform competitive baselines across a variety of FL scenarios.
title Enhancing Gradient Inversion Attacks in Federated Learning via Hierarchical Feature Optimization
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2604.00955