Evaluating Gradient Inversion Attacks and Defenses in Federated Learning
–Neural Information Processing Systems
Gradient inversion attack (or input recovery from gradient) is an emerging threat to the security and privacy preservation of Federated learning, whereby malicious eavesdroppers or participants in the protocol can recover (partially) the clients' private data. This paper evaluates existing attacks and defenses. We find that some attacks make strong assumptions about the setup. Relaxing such assumptions can substantially weaken these attacks. We then evaluate the benefits of three proposed defense mechanisms against gradient inversion attacks.
Neural Information Processing Systems
Oct-10-2024, 02:02:55 GMT