LE QUY DON
Technical University
VietnameseClear Cookie - decide language by browser settings

EncGradInversion: Image Encoding and Gradient Inversion-Based Batch Attack in Federated Learning

Dao, T.-N. and Lee, H. (2024) EncGradInversion: Image Encoding and Gradient Inversion-Based Batch Attack in Federated Learning. IEEE Internet of Things Journal.

Full text not available from this repository. (Upload)

Abstract

The gradient attack problem has recently been studied to increase the awareness of people on privacy risks in federated learning. However, this attack is constrained under specific conditions such as small image batch sizes and low image resolutions. To address this challenge, we introduce a new three-phase image recovery architecture called EncGradInversion, which harnesses the power of image encoding and the shared gradient inversion. In the first phase, we attempt to extract the representation for all of the images using the gradient at the last layer. Then, in the second phase, the extracted encoding of a specific image is leveraged for reconstructing the image by matching the representation of dummy and approximated images. This allows a parallel algorithm to accelerate the image recovery. In the last phase, the reconstructed images are fine-tuned using the shared gradient of the whole network. In the second and third phases, we formulate an optimization problem to minimize the discrepancy between the shared and reconstructed gradients, while preserving the smoothness and natural appearance of the reconstructed images. Evaluated on various datasets and deep learning models, EncGradInversion shows its superiority to recover the original training images with resolutions as high as 1024×1024 and with the batch size of 512. Furthermore, the proposed architecture outperforms existing counterparts with a factor of up to 9.8 and 6.04, in terms of structural similarity performance and attack time. © 2014 IEEE.

Item Type: Article
Divisions: Offices > Office of International Cooperation
Identification Number: 10.1109/JIOT.2024.3483850
Uncontrolled Keywords: Contrastive Learning; Differential privacy; Image matching; Image reconstruction; Information leakage, Batch sizes; Condition; Gradient inversion; Gradient leakage attack; Image encoding; Image gradients; Image recovery; Privacy risks; Reconstructed image; Second phase, Federated learning
URI: http://eprints.lqdtu.edu.vn/id/eprint/11435

Actions (login required)

View Item
View Item