A High-Dimensional Gradient Inversion Attack Based on Feature Distillation in Federated Learning
摘要
As a privacy protection framework, federated learning enables all clients to collaboratively train a global model while ensuring that their data remains within the local domain. However, the occurrence of gradient inversion attacks reveals that the transmission of gradients still brings the risk of data reconstruction. For the current gradient inversion attacks, it is very likely to fall into a local optimal solution and is also prone to causing reconstruction failure. Moreover, the quality of the reconstructed data needs to be further improved. Therefore, in this paper, we propose a high-dimensional gradient inversion attack model based on feature distillation (F-HGIA). Firstly, to accelerate the reconstruction speed and make the reconstruction approach the global optimal solution, the performance-sensitive features extracted based on feature distillation are used as prior knowledge to generate the initial reconstructed data. Secondly, the gradients are encoded in high dimension to avoid the incompletely reversible process of encoding and decoding. The experimental results on three datasets show that the proposed F-HGIA outperforms baseline methods in terms of the various metrics including peak signal-to-noise ratio (PSNR), structural similarity (SSIM), and learning perception image block similarity (LPIPS).