论文

PI-SME 路径积分代理模型提升联邦学习梯度反转攻击效果

A Path Integral Surrogate for Multi-Step Gradient Inversion in Federated Learning

精选理由

这篇 arXiv 论文提出 PI-SME,把梯度反转攻击的代理模型从单点升级成路径积分近似,在 CIFAR-100 和 FEMNIST 上重建私有图像比之前的基线更准。做联邦学习隐私的可以看看。

联邦学习中客户端只上传模型更新以保护隐私,梯度反转攻击却能从更新中重建私有图像。论文提出 PI-SME(Path-Integral Surrogate Model Extension),把 FedAvg 下多步本地训练的累计更新视为梯度场的路径积分,用 Gauss–Legendre 求积在可学习 Bézier 路径上多个节点近似。此前最强代理基线只在单点读取梯度。在 CIFAR-100 和 FEMNIST 上跨多种轨迹长度和类别受限批次,PI-SME 在多项反转指标和匹配损失上重建效果更好。

原文 · arXiv cs.LG

A Path Integral Surrogate for Multi-Step Gradient Inversion in Federated Learning

Federated learning lets many clients train a shared model together without ever sending their private data to a central server. Each client shares only a model update, and this update should reveal far less about the client than its raw training examples would. This premise is what protects the privacy of the clients. Gradient inversion attacks challenge it directly by trying to reconstruct a client's private input images from the single update it shared. Under FedAvg, a client's update accumulates several local training steps, so the server sees only the two endpoints of a hidden weight trajectory. Recent gradient inversion attacks fit a surrogate model along the path between these two endpoints but they still read its gradient at a single point. We propose the Path-Integral Surrogate Model Extension (PI-SME) which treats the accumulated update as a path integral of the gradient field and approximates it by Gauss--Legendre quadrature over several nodes along a learnable Bézier path. On CIFAR-100 and FEMNIST images across a range of trajectory lengths and class-restricted batches PI-SME reconstructs the private inputs more faithfully than the strongest surrogate baseline on several inversion metrics and the matching loss.