跳到正文
arXiv:cs.LG· Viktor Valadi, Lucas Beerens, Mattias {\AA}kesson, Johan \"Ostman, Fazeleh Hoseini, Salman Toor, Andreas Hellander·· 5 小时前AI 评分45

梯度反转攻击在联邦学习中的实际可行性研究

Practical Feasibility of Gradient Inversion Attacks in Federated Learning

AI 导读

一项覆盖图像分类与目标检测任务的系统研究表明,现代性能优化模型在联邦学习中对梯度反转攻击具有一致的视觉抗性,难以被有效重建。许多已报道的攻击成功依赖推理模式运行或架构简化等上限设置,并不反映真实训练流程。在诚实但好奇的服务器假设下,高保真图像重建不构成生产级联邦学习系统的关键隐私风险。

正文

View PDF HTML (experimental)

Abstract:Gradient inversion attacks are often presented as a serious privacy threat in federated learning, with recent work reporting increasingly strong reconstructions under favorable experimental settings. However, it remains unclear whether such attacks are feasible in modern, performance-optimized systems deployed in practice. In this work, we evaluate the practical feasibility of gradient inversion for image-based federated learning. We conduct a systematic study across multiple datasets and tasks, including image classification and object detection, using canonical vision architectures at contemporary resolutions. Our results show that while gradient inversion remains possible for certain legacy or transitional designs under highly restrictive assumptions, modern, performance-optimized models consistently resist meaningful reconstruction visually. We further demonstrate that many reported successes rely on upper-bound settings, such as inference mode operation or architectural simplifications which do not reflect realistic training pipelines. Taken together, our findings indicate that, under an honest-but-curious server assumption, high-fidelity image reconstruction via gradient inversion does not constitute a critical privacy risk in production-optimized federated learning systems, and that practical risk assessments must carefully distinguish diagnostic attack settings from real-world deployments.
Comments: v3: revised manuscript; expanded experiments; added new feasibility probe;
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Machine Learning (cs.LG)
Cite as: arXiv:2508.19819 [cs.CR]
  (or arXiv:2508.19819v3 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2508.19819

arXiv-issued DOI via DataCite

Submission history

From: Viktor Valadi [view email]
[v1] Wed, 27 Aug 2025 12:07:23 UTC (1,043 KB)
[v2] Mon, 9 Feb 2026 14:36:04 UTC (2,035 KB)
[v3] Tue, 6 Oct 2026 13:02:26 UTC (2,234 KB)

来源:arXiv:cs.LG · arxiv.org