Inverting Gradients - How easy is it to break privacy in federated learning?

Jonas GeipingHartmut BauermeisterHannah DrögeMichael Moeller

article2020NeurIPS1,779 citations

Demonstrates that shared parameter gradients in federated learning can be inverted to reconstruct high-resolution training images, proving that gradient averaging and deep architectures fail to protect user privacy.

Listen

Federated learning is widely adopted across privacy-sensitive industries, such as healthcare and mobile communications, under the premise that user data remains confidential because participants share only model parameter updates (gradients) rather than raw information. The article investigates the security of this core assumption. Its primary objective is to evaluate whether an honest-but-curious server can reconstruct private training images from transmitted parameter updates and to establish the boundaries of this vulnerability in deep, practical machine learning systems.

The authors conducted a comprehensive theoretical and empirical investigation using standard computer vision benchmark datasets (CIFAR-10, CIFAR-100, and ImageNet) across realistic convolutional and residual network architectures of varying depths (such as ResNet-18 up to ResNet-152). Rather than relying on previous reconstruction techniques that fail on deep, trained models, the authors developed a magnitude-invariant optimization method based on cosine similarity and signed momentum-based gradient updates, paired with basic image regularization. They evaluated this method across single-image scenarios, fully trained networks, and complex federated averaging settings involving local multi-epoch updates and large image batches.

The analysis yielded four major findings. First, inputs to any fully connected network layer can be derived mathematically from parameter gradients alone, independent of the rest of the architecture. Second, the proposed numerical approach reconstructs high-resolution images even from fully trained, deep networks such as ResNet-152, where previous methods failed completely. Third, traditional architectural scaling offers no meaningful "defense-in-depth": increasing network width and depth maintains high reconstruction fidelity, while standard zero-padding unintentionally leaks spatial positioning. Finally, common defensive practices like federated averaging (performing up to 100 local update steps) or aggregating multiple images do not secure privacy; the authors successfully recovered recognizable images even when averaged across a batch of 100 images.

These findings demonstrate that standard federated learning provides a false sense of security. Sharing model updates poses significant privacy, legal, and compliance risks for organizations handling sensitive proprietary or personal data. Because architectural complexity, local training steps, and batch aggregation fail to prevent reconstruction, basic federated learning alone cannot meet strict data protection standards.

Organizations must not treat basic federated learning as a sufficient standalone privacy safeguard. Stakeholders should instead implement provable defenses, specifically differential privacy or secure multiparty aggregation, despite the potential trade-offs in model accuracy and computational overhead. Further engineering research is needed to design lightweight defense mechanisms and verification tools that can evaluate vulnerability to gradient inversion prior to model deployment.

While the findings confidently prove fundamental privacy vulnerabilities in computer vision tasks, the reconstruction quality for individual images in large batches varies, and trained networks can introduce visual artifacts or obscure fine background details. Nonetheless, decision-makers should operate under the assumption that shared model gradients leak substantial private information unless mathematically guaranteed protections are in place.

Cover for Inverting Gradients - How easy is it to break privacy in federated learning?

Abstract

The idea of federated learning is to collaboratively train a neural network on a server. Each user receives the current weights of the network and in turns sends parameter updates (gradients) based on local data. This protocol has been designed not only to train neural networks data-efficiently, but also to provide privacy benefits for users, as their input data remains on device and only parameter gradients are shared. But how secure is sharing parameter gradients? Previous attacks have provided a false sense of security, by succeeding only in contrived settings - even for a single image. However, by exploiting a magnitude-invariant loss along with optimization strategies based on adversarial attacks, we show that is is actually possible to faithfully reconstruct images at high resolution from the knowledge of their parameter gradients, and demonstrate that such a break of privacy is possible even for trained deep networks. We analyze the effects of architecture as well as parameters on the difficulty of reconstructing an input image and prove that any input to a fully connected layer can be reconstructed analytically independent of the remaining architecture. Finally we discuss settings encountered in practice and show that even averaging gradients over several iterations or several images does not protect the user's privacy in federated learning applications in computer vision.

Table of Contents

  • 1 Introduction
  • 2 Related Work
  • 3 Theoretical Analysis: Recovering Images from their Gradients
  • 4 A Numerical Reconstruction Method
  • 5 Single Image Reconstruction from a Single Gradient
  • 6 Distributed Learning with Federated Averaging and Multiple Images
  • 7 Conclusions
  • References
  • A Variations of the threat model
  • A.1 Dishonest Architectures
  • A.2 Dishonest Parameter Vectors
  • B Experimental Details
  • B.1 Federated Averaging
  • B.2 ConvNet
  • B.3 Ablation Study
  • C Hyperparameter Settings
  • C.1 Settings for the experiments in Sec. 5
  • C.2 Setting for experiments in Sec. 6
  • D Proofs for section 3.1
  • E Additional Examples
  • E.1 Additional CIFAR-10 examples
  • E.2 Visualization of experiments in Sec. 5
  • E.3 More ImageNet examples for Sec. 5
  • E.4 Multi-Image Recovery of Sec. 6
  • E.5 General case of Sec. 6

Knowls

  1. Knowl 1 — Cosine Similarity and Total Variation Objective for Gradient Inversion

    model/method

    To reconstruct a private training image x∗∈[0,1]nx^* \in [0, 1]^n with corresponding label yy from its shared parameter gradient ∇θLθ(x∗,y)∈Rp\nabla_\theta \mathcal{L}_\theta(x^*, y) \in \mathbb{R}^p with respect to model parameters θ\theta, the optimization problem is formulated as:

    x=arg⁡min⁡x∈[0,1]n1−⟨∇θLθ(x,y),∇θLθ(x∗,y)⟩∥∇θLθ(x,y)∥∥∇θLθ(x∗,y)∥+αTV(x)x = \arg\min_{x \in [0,1]^n} 1 - \frac{\langle \nabla_\theta \mathcal{L}_\theta(x, y), \nabla_\theta \mathcal{L}_\theta(x^*, y) \rangle}{\|\nabla_\theta \mathcal{L}_\theta(x, y)\| \|\nabla_\theta \mathcal{L}_\theta(x^*, y)\|} + \alpha \text{TV}(x)

    where Lθ(⋅,y)\mathcal{L}_\theta(\cdot, y) denotes the loss function evaluated on input xx and label yy, ⟨⋅,⋅⟩\langle \cdot, \cdot \rangle is the Euclidean inner product, ∥⋅∥\|\cdot\| denotes the ℓ2\ell_2-norm, TV(x)\text{TV}(x) is the total variation image prior regularizer, and α≥0\alpha \ge 0 is the regularization weight.

    The cosine similarity cost is used instead of Euclidean distance because the norm magnitude of a parameter gradient primarily reflects the convergence state of the model on the data point, whereas the high-dimensional directional angle captures the semantic feature prediction impact. Minimizing cosine distance aligns the model updates caused by xx with those caused by x∗x^* regardless of gradient vanishing in well-trained networks.

  2. Knowl 2 — Analytic Input Reconstruction for Biased Fully Connected Layers

    theoretical result

    For any neural network containing a biased fully connected layer preceded solely by (possibly unbiased) fully connected layers, the input to the network can be reconstructed analytically and uniquely from the network's parameter gradients without numerical optimization, provided that the gradient of the loss with respect to the layer's output contains at least one non-zero entry.

    Specifically, consider a fully connected layer with input xl∈Rnlx_l \in \mathbb{R}^{n_l}, weight matrix Al∈Rnl+1×nlA_l \in \mathbb{R}^{n_{l+1} \times n_l}, bias vector bl∈Rnl+1b_l \in \mathbb{R}^{n_{l+1}}, intermediate affine output yl=Alxl+bly_l = A_l x_l + b_l, and activation output xl+1=max⁡{yl,0}x_{l+1} = \max\{y_l, 0\}. If there exists an index i∈{1,…,nl+1}i \in \{1, \dots, n_{l+1}\} such that ∂L∂(bl)i≠0\frac{\partial \mathcal{L}}{\partial (b_l)_i} \neq 0, the input vector xlx_l is uniquely determined by:

    xl=(∂L∂(bl)i)−1(∂L∂(Al)i,:)Tx_l = \left(\frac{\partial \mathcal{L}}{\partial (b_l)_i}\right)^{-1} \left(\frac{\partial \mathcal{L}}{\partial (A_l)_{i,:}}\right)^T

    where (Al)i,:(A_l)_{i,:} denotes the ii-th row of AlA_l, ∂L∂(Al)i,:\frac{\partial \mathcal{L}}{\partial (A_l)_{i,:}} is the gradient of the loss L\mathcal{L} with respect to that row, and ∂L∂(bl)i\frac{\partial \mathcal{L}}{\partial (b_l)_i} is the gradient with respect to the ii-th bias component.

    For networks ending in a fully connected classification layer, this enables exact analytic recovery of the final convolutional feature representations directly from the classification layer gradients, showing that gradient inversion is strictly easier than inversion from intermediate visual representations.

  3. Knowl 3 — Signed-Gradient Adam Optimization for Gradient Inversion

    algorithm

    To solve the non-smooth, non-convex gradient inversion objective for deep networks (such as ResNets with discontinuous higher-order derivatives from ReLU activations), the reconstruction is performed using the Adam optimizer applied exclusively to the sign of the objective gradient with respect to the candidate image xx.

    Input: Observed target gradient G∗=∇θLθ(x∗,y)G^* = \nabla_\theta \mathcal{L}_\theta(x^*, y), network parameters θ\theta, target label yy, total iterations TT, base learning rate η0\eta_0, TV weight α\alpha
    Output: Reconstructed image x∈[0,1]nx \in [0, 1]^n
    Initialize x0∼N(0,In)x_0 \sim \mathcal{N}(0, I_n)
    Initialize Adam momentum buffers m0←0m_0 \leftarrow 0, v0←0v_0 \leftarrow 0
    for t=0t = 0 to T−1T-1 do
        loss(xt)=1−⟨∇θLθ(xt,y),G∗⟩∥∇θLθ(xt,y)∥∥G∗∥+αTV(xt)\text{loss}(x_t) = 1 - \frac{\langle \nabla_\theta \mathcal{L}_\theta(x_t, y), G^* \rangle}{\|\nabla_\theta \mathcal{L}_\theta(x_t, y)\| \|G^*\|} + \alpha \text{TV}(x_t)
        gt=∇xtloss(xt)g_t = \nabla_{x_t} \text{loss}(x_t)
        g~t=sign(gt)\tilde{g}_t = \text{sign}(g_t)
        
        if t∈{⌊38T⌋,⌊58T⌋,⌊78T⌋}t \in \{\lfloor \frac{3}{8} T \rfloor, \lfloor \frac{5}{8} T \rfloor, \lfloor \frac{7}{8} T \rfloor\} then
            η←0.1⋅η\eta \leftarrow 0.1 \cdot \eta
        else
            η←η0\eta \leftarrow \eta_0
        end if
        
        Update mt+1,vt+1m_{t+1}, v_{t+1} using Adam rules on g~t\tilde{g}_t
        xt+1←xt−AdamStep(mt+1,vt+1,η)x_{t+1} \leftarrow x_t - \text{AdamStep}(m_{t+1}, v_{t+1}, \eta)
        xt+1←clip(xt+1,0,1)x_{t+1} \leftarrow \text{clip}(x_{t+1}, 0, 1)
    end for
    return xTx_T

    The sign operator sign(⋅)\text{sign}(\cdot) stabilizes the step directions against vanishing or exploding higher-order derivative magnitudes across intermediate layers, while Adam's accumulated momentum maintains unsigned update steps for continuous convergence. In typical setups, T=4800T = 4800 to 2400024000 iterations and η0∈[0.01,1.0]\eta_0 \in [0.01, 1.0].

  4. Knowl 4 — Gradient Inversion Formulation for Federated Averaging

    model/method

    In Federated Averaging (FedAvg), a client performs l=EnBl = E \frac{n}{B} local stochastic gradient descent steps with step size τ\tau across EE local epochs on nn private images using mini-batch size BB. The client transmits the cumulative parameter change θ~k+l−θk=−τ∑m=1l∇θk+m−1Lθk+m−1(x∗,y)\tilde{\theta}^{k+l} - \theta^k = -\tau \sum_{m=1}^l \nabla_{\theta^{k+m-1}} \mathcal{L}_{\theta^{k+m-1}}(x^*, y) to the server.

    The server reconstructs the batch x∗x^* by matching the unrolled trajectory of cumulative gradient updates:

    x=arg⁡min⁡x∈[0,1]n1−⟨∑m=1l∇θk+m−1Lθk+m−1(x,y), ∑m=1l∇θk+m−1Lθk+m−1(x∗,y)⟩∥∑m=1l∇θk+m−1Lθk+m−1(x,y)∥∥∑m=1l∇θk+m−1Lθk+m−1(x∗,y)∥+αTV(x)x = \arg\min_{x \in [0,1]^n} 1 - \frac{\left\langle \sum_{m=1}^l \nabla_{\theta^{k+m-1}} \mathcal{L}_{\theta^{k+m-1}}(x, y), \, \sum_{m=1}^l \nabla_{\theta^{k+m-1}} \mathcal{L}_{\theta^{k+m-1}}(x^*, y) \right\rangle}{\left\|\sum_{m=1}^l \nabla_{\theta^{k+m-1}} \mathcal{L}_{\theta^{k+m-1}}(x, y)\right\| \left\|\sum_{m=1}^l \nabla_{\theta^{k+m-1}} \mathcal{L}_{\theta^{k+m-1}}(x^*, y)\right\|} + \alpha \text{TV}(x)

    where θk+m=θk+m−1−τ∇θk+m−1Lθk+m−1(x,y)\theta^{k+m} = \theta^{k+m-1} - \tau \nabla_{\theta^{k+m-1}} \mathcal{L}_{\theta^{k+m-1}}(x, y) represents the simulated local parameter update trajectory. The objective gradient with respect to xx is computed via automatic differentiation backpropagating through the sequence of ll update steps.

  5. Knowl 5 — Reconstruction Performance of Cosine-Adam vs Euclidean L-BFGS Across Architectures

    data/table

    Reconstruction quality measured in Peak Signal-to-Noise Ratio (PSNR, mean ±\pm standard deviation in dB) was evaluated on the first 100 images of the CIFAR-10 validation set. The comparison evaluates the cosine similarity loss optimized with signed Adam against the Euclidean loss optimized with L-BFGS (with 16 restarts for LeNet and 8 restarts for ResNet) on both untrained and trained instances of a shallow CNN (LeNet-Zhu) and a deep residual network (ResNet20-4).

    Architecture LeNet (Zhu) ResNet20-4
    Trained False True False True
    Euclidean Loss + L-BFGS 46.25±12.6646.25 \pm 12.66 13.24±5.4413.24 \pm 5.44 10.29±5.3810.29 \pm 5.38 6.90±2.806.90 \pm 2.80
    Proposed (Cosine + Signed Adam) 18.00±3.3318.00 \pm 3.33 18.08±4.2718.08 \pm 4.27 19.83±2.9619.83 \pm 2.96 13.95±3.3813.95 \pm 3.38

    The Euclidean loss with L-BFGS achieves high PSNR on smooth, shallow, untrained architectures, but fails completely on deep trained ResNet models (6.90 dB6.90\text{ dB}). In contrast, the cosine similarity and signed Adam approach reliably inverts gradients for trained deep networks (13.95 dB13.95\text{ dB} on trained ResNet20-4 and scalable to ResNet-152 on ImageNet), recovering recognizable image content across all trained architectures.

  6. Knowl 6 — Ablation Study of Loss and Optimization Components in Gradient Inversion

    data/table

    An ablation study on the first 10 images of the CIFAR-10 validation set using a trained ResNet-18 model demonstrates the relative contributions of the optimizer, the cosine similarity loss, the signed gradient update, and total variation (TV) regularization to gradient inversion quality (measured in PSNR in dB, with standard error in parentheses).

    Configuration Reconstruction PSNR (dB)
    Basic Setup (Cosine Similarity + Signed Adam + TV) 20.12±1.0220.12 \pm 1.02
    L2L_2 Loss instead of cosine similarity 15.13±0.7015.13 \pm 0.70
    Without total variation 19.96±0.7519.96 \pm 0.75
    With L-BFGS instead of Adam 5.13±0.505.13 \pm 0.50

    Replacing Adam with L-BFGS causes catastrophic failure (dropping PSNR by 14.99 dB14.99\text{ dB} to 5.13 dB5.13\text{ dB}) due to discontinuous second-order derivatives in ReLU networks. Replacing cosine similarity with Euclidean L2L_2 distance reduces reconstruction quality by 4.99 dB4.99\text{ dB}. Total variation regularization provides a modest quantitative improvement (+0.16 dB+0.16\text{ dB}) while removing high-frequency visual artifacts.

  7. Knowl 7 — Effects of Network Depth, Network Width, and Convolutional Padding on Inversion Vulnerability

    empirical result

    Empirical analysis of convolutional neural network properties demonstrates how network structure affects gradient inversion vulnerability:

    • Network Depth: Reconstructing input images does not degrade substantially as network depth increases. Attacks successfully reconstruct ImageNet validation images (224×224224 \times 224 pixels) from gradients of trained ResNet-18, ResNet-34, ResNet-50, and ResNet-152 models, showing that deep networks provide no inherent "defense-in-depth" against gradient inversion.
    • Network Width: Increasing the number of convolutional channels in ResNet-18 from base width 16 to 64 to 128 increases reconstruction quality on CIFAR-10 images (average PSNR increases from 19.02 dB19.02\text{ dB} to 22.04 dB22.04\text{ dB} to 22.94 dB22.94\text{ dB}). Wider networks increase the parameter-to-pixel ratio, yielding more gradient constraints per input pixel.
    • Convolutional Padding: Standard zero-padding in convolutional layers breaks translational invariance, allowing gradient inversion to recover the exact spatial position of objects. When circular padding is used to enforce true translational invariance, reconstructed images separate into shifted components, obscuring spatial localization.
  8. Knowl 8 — Reconstruction Quality Across Multi-Step and Multi-Image Federated Averaging Configurations

    data/table

    Reconstruction quality (measured in PSNR, mean ±\pm standard deviation in dB) was evaluated across 100 trials on the CIFAR-10 validation set using an untrained ConvNet under various Federated Averaging parameter combinations of local epochs EE, local dataset size nn, and mini-batch size BB.

    Setting 1 Epoch (E=1E = 1) 5 Epochs (E=5E = 5)
    Images (nn) n=4n = 4 n=8n = 8 n=8n = 8 n=1n = 1 n=8n = 8
    Batch size (BB) B=2B = 2 B=2B = 2 B=8B = 8 B=1B = 1 B=8B = 8
    PSNR (dB) 16.92±2.1016.92 \pm 2.10 14.66±1.1214.66 \pm 1.12 16.49±1.0216.49 \pm 1.02 25.05±3.2825.05 \pm 3.28 16.58±0.9616.58 \pm 0.96

    Increasing the number of local epochs does not hinder reconstruction: 8-image full-batch reconstruction achieves 16.58 dB16.58\text{ dB} over 5 epochs compared to 16.49 dB16.49\text{ dB} for 1 epoch, and single-image recovery across 100 local gradient descent steps preserves PSNR (~19.39 dB19.39\text{ dB} vs 19.77 dB19.77\text{ dB} for 1 step at learning rate τ=10−4\tau = 10^{-4}).

    Furthermore, gradient averaging over batches as large as n=100n = 100 images (evaluated on CIFAR-100 with ResNet32-10) does not produce uniform distortion; several individual images within the 100-image batch remain clearly recognizable and compromised.

  9. Knowl 9 — Honest-but-Curious Threat Model and Dishonest Server Attack Strategies in Federated Learning

    assumption

    Federated gradient inversion operates under an honest-but-curious server threat model: the server passively stores and processes model parameter updates transmitted by clients to reconstruct private user data, but strictly adheres to the protocol without modifying the shared architecture or sending corrupt/synthetic global parameters.

    If the server behaves dishonestly, gradient inversion becomes significantly easier:

    1. Dishonest Architecture: The server can insert a fully connected layer as the first network layer, insert reversible blocks, or create separate parameter sub-models per client batch item, enabling direct or analytic reconstruction of private inputs.
    2. Dishonest Parameter Vectors: The server can set convolutional weights to identity operators, passing inputs unaltered directly to the classification layer.
    3. Label Flipping: The server can permute two rows in the weight matrix and bias vector of the final classification layer. This tricks the client into computing loss gradients with respect to an incorrect label, boosting gradient magnitude and eliminating the gradient-diminishing effect of trained models without raising detection on the client side.

Coverage note — Deliberately omitted qualitative image galleries in the supplementary material (Figures 10-20), as they provide visual illustrations supporting the quantified empirical findings already captured in the knowls.

References

  1. 1.Anish Athalye, Nicholas Carlini, and David Wagner. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. arXiv:1802.00420 [cs], February 2018.
  2. 2.Martin Benning and Martin Burger. Modern regularization methods for inverse problems. Acta Numerica, 27:1–111, May 2018.
  3. 3.Keith Bonawitz, Hubert Eichner, Wolfgang Grieskamp, Dzmitry Huba, Alex Ingerman, Vladimir Ivanov, Chloe Kiddon, Jakub Konecný, Stefano Mazzocchi, H. Brendan McMahan, Timon Van Overveldt, David Petrou, Daniel Ramage, and Jason Roselander. Towards Federated Learning at Scale: System Design. arXiv:1902.01046 [cs, stat], March 2019.
  4. 4.E. J. Candes, J. Romberg, and T. Tao. Robust uncertainty principles: Exact signal reconstruction from highly incomplete frequency information. IEEE Transactions on Information Theory, 52(2):489–509, February 2006.
  5. 5.Bo Chang, Lili Meng, Eldad Haber, Lars Ruthotto, David Begert, and Elliot Holtham. Reversible Architectures for Arbitrarily Deep Residual Neural Networks. arXiv:1709.03698 [cs, stat], September 2017.
  6. 6.Guillaume Charpiat, Nicolas Girard, Loris Felardos, and Yuliya Tarabalka. Input Similarity from the Neural Network Perspective. In Advances in Neural Information Processing Systems 32, pages 5342–5351. Curran Associates, Inc., 2019.
  7. 7.Trishul Chilimbi, Yutaka Suzue, Johnson Apacible, and Karthik Kalyanaraman. Project Adam: Building an Efficient and Scalable Deep Learning Training System. In 11th {USENIX} Symposium on Operating Systems Design and Implementation ({OSDI} 14), pages 571–582, 2014.
  8. 8.Alexey Dosovitskiy and Thomas Brox. Generating Images with Perceptual Similarity Metrics based on Deep Networks. In Advances in Neural Information Processing Systems 29, pages 658–666. Curran Associates, Inc., 2016.
  9. 9.Alexey Dosovitskiy and Thomas Brox. Inverting Visual Representations With Convolutional Networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pages 4829–4837, 2016.
  10. 10.Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS ’15, pages 1322–1333, Denver, Colorado, USA, October 2015. Association for Computing Machinery.
  11. 11.Karan Ganju, Qi Wang, Wei Yang, Carl A. Gunter, and Nikita Borisov. Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant Representations. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pages 619–633, Toronto Canada, January 2018. ACM.
  12. 12.Micah Goldblum, Jonas Geiping, Avi Schwarzschild, Michael Moeller, and Tom Goldstein. Truth or Backpropaganda? An Empirical Investigation of Deep Learning Theory. arXiv:1910.00359 [cs, math, stat], October 2019.
  13. 13.Jörn-Henrik Jacobsen, Arnold Smeulders, and Edouard Oyallon. I-RevNet: Deep Invertible Networks. arXiv:1802.07088 [cs, stat], February 2018.
  14. 14.Bargav Jayaraman and David Evans. Evaluating Differentially Private Machine Learning in Practice. arXiv:1902.08874 [cs, stat], August 2019.
  15. 15.Arthur Jochems, Timo M. Deist, Issam El Naqa, Marc Kessler, Chuck Mayo, Jackson Reeves, Shruti Jolly, Martha Matuszak, Randall Ten Haken, Johan van Soest, Cary Oberije, Corinne Faivre-Finn, Gareth Price, Dirk de Ruysscher, Philippe Lambin, and Andre Dekker. Developing and Validating a Survival Prediction Model for NSCLC Patients Through Distributed Learning Across 3 Countries. International Journal of Radiation OncologyBiologyPhysics, 99(2):344–352, October 2017.
  16. 16.Arthur Jochems, Timo M. Deist, Johan van Soest, Michael Eble, Paul Bulens, Philippe Coucke, Wim Dries, Philippe Lambin, and Andre Dekker. Distributed learning: Developing a predictive model based on data from multiple hospitals without data leaving the hospital – A real life proof of concept. Radiotherapy and Oncology, 121(3):459–467, December 2016.
  17. 17.Diederik P. Kingma and Jimmy Ba. Adam: A Method for Stochastic Optimization. In International Conference on Learning Representations (ICLR), San Diego, May 2015.
  18. 18.Pang Wei Koh and Percy Liang. Understanding Black-box Predictions via Influence Functions. In International Conference on Machine Learning, pages 1885–1894, July 2017.
  19. 19.Jakub Konecný, Brendan McMahan, and Daniel Ramage. Federated Optimization:Distributed Optimization Beyond the Datacenter. arXiv:1511.03575 [cs, math], November 2015.
  20. 20.Alex Krizhevsky, Ilya Sutskever, and Geoffrey E. Hinton. Imagenet classification with deep convolutional neural networks. In Advances in Neural Information Processing Systems, pages 1097–1105, 2012.
  21. 21.Dong C. Liu and Jorge Nocedal. On the limited memory BFGS method for large scale optimization. Mathematical Programming, 45(1-3):503–528, August 1989.
  22. 22.Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv:1706.06083 [cs, stat], June 2017.
  23. 23.Aravindh Mahendran and Andrea Vedaldi. Visualizing Deep Convolutional Neural Networks Using Natural Pre-images. International Journal of Computer Vision, 120(3):233–255, December 2016.
  24. 24.H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Agüera y Arcas. Communication-Efficient Learning of Deep Networks from Decentralized Data. arXiv:1602.05629 [cs], February 2017.
  25. 25.H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. Learning Differentially Private Recurrent Language Models. arXiv:1710.06963 [cs], February 2018.
  26. 26.Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. Exploiting Unintended Feature Leakage in Collaborative Learning. In 2019 IEEE Symposium on Security and Privacy (SP), pages 691–706, May 2019.
  27. 27.Le Trieu Phong, Yoshinori Aono, Takuya Hayashi, Lihua Wang, and Shiho Moriai. Privacy-Preserving Deep Learning: Revisited and Enhanced. In Applications and Techniques in Information Security, Communications in Computer and Information Science, pages 100–110, Singapore, 2017. Springer.
  28. 28.Le Trieu Phong, Yoshinori Aono, Takuya Hayashi, Lihua Wang, and Shiho Moriai. Privacy-Preserving Deep Learning via Additively Homomorphic Encryption. Technical Report 715, 2017.
  29. 29.Sashank Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett, Keith Rush, Jakub Konecný, Sanjiv Kumar, and H. Brendan McMahan. Adaptive Federated Optimization. arXiv:2003.00295 [cs, math, stat], February 2020.
  30. 30.Leonid I. Rudin, Stanley Osher, and Emad Fatemi. Nonlinear total variation based noise removal algorithms. Physica D: Nonlinear Phenomena, 60(1):259–268, November 1992.
  31. 31.Reza Shokri and Vitaly Shmatikov. Privacy-Preserving Deep Learning. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security - CCS ’15, pages 1310–1321, Denver, Colorado, USA, 2015. ACM Press.
  32. 32.Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks. In arXiv:1312.6199 [Cs], December 2013.
  33. 33.Michael Veale, Reuben Binns, and Lilian Edwards. Algorithms that remember: Model inversion attacks and data protection law. Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences, 376(2133):20180083, November 2018.
  34. 34.Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. Beyond Inferring Class Representatives: User-Level Privacy Leakage From Federated Learning. arXiv:1812.00535 [cs], December 2018.
  35. 35.Qiang Yang, Yang Liu, Tianjian Chen, and Yongxin Tong. Federated Machine Learning: Concept and Applications. arXiv:1902.04885 [cs], February 2019.
  36. 36.Yuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang, Bo Li, and Dawn Song. The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks. arXiv:1911.07135 [cs, stat], November 2019.
  37. 37.Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. iDLG: Improved Deep Leakage from Gradients. arXiv:2001.02610 [cs, stat], January 2020.
  38. 38.Ligeng Zhu, Zhijian Liu, and Song Han. Deep Leakage from Gradients. In Advances in Neural Information Processing Systems 32, pages 14774–14784. Curran Associates, Inc., 2019.

Citation

MLA
Geiping, J., et al. “Inverting Gradients -- How Easy Is It to Break Privacy in Federated Learning?”. arXiv, 2020, http://arxiv.org/abs/2003.14053v2.
APA
Geiping, J., Bauermeister, H., Dröge, H., & Moeller, M. (2020). Inverting Gradients -- How easy is it to break privacy in federated learning?. arXiv. http://arxiv.org/abs/2003.14053v2
Chicago
Geiping, J., H. Bauermeister, H. Dröge, and M. Moeller. 2020. “Inverting Gradients -- How Easy Is It to Break Privacy in Federated Learning?”. arXiv. http://arxiv.org/abs/2003.14053v2.
Harvard
Geiping, J. et al. (2020) “Inverting Gradients -- How easy is it to break privacy in federated learning?”, arXiv [Preprint]. Available at: http://arxiv.org/abs/2003.14053v2.
Vancouver
1. Geiping J, Bauermeister H, Dröge H, Moeller M (2020) Inverting Gradients -- How easy is it to break privacy in federated learning?. arXiv

BibTeX

@article{geiping2020inverting,
  title = {Inverting Gradients -- How easy is it to break privacy in federated learning?},
  author = {Geiping, Jonas and Bauermeister, Hartmut and Dröge, Hannah and Moeller, Michael},
  year = {2020},
  journal = {arXiv},
  url = {http://arxiv.org/abs/2003.14053v2},
  eprint = {2003.14053}
}
Metadata:arXiv

Source Code

This paper has an official code repository available. Click below to access the source code.

View Repository

Access the Paper

This paper is available from its original source. Click below to access the PDF.

Open PDF
License: Authors