Inverting Gradients - How easy is it to break privacy in federated learning?

Inverting Gradients - How easy is it to break privacy in federated learning?
复制标题

DOI:
--
复制
发表时间:
2020-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Jonas Geiping;Hartmut Bauermeister;Hannah Dröge;Michael Moeller
Jonas Geiping;Hartmut Bauermeister;Hannah Dröge;Michael Moeller
中科院分区:
其他
文献类型:
--
作者:
Jonas Geiping;Hartmut Bauermeister;Hannah Dröge;Michael Moeller

文献摘要

被引文献

相似文献

联邦学习的思想是在服务器上协作训练神经网络。每个用户接收网络的当前权重,然后根据本地数据发送参数更新(梯度)。该协议不仅可以有效地训练神经网络数据,还可以为用户提供隐私优势,因为他们的输入数据保留在设备上,并且只共享参数梯度。但是共享参数梯度的安全性如何呢?以前的攻击提供了一种虚假的安全感,只在人为的设置中成功-即使是一个单一的图像。然而,通过利用幅度不变损失沿着基于对抗性攻击的优化策略,我们证明了实际上可以根据其参数梯度的知识以高分辨率忠实地重建图像,并证明即使对于经过训练的深度网络,这种隐私的破坏也是可能的。我们分析了结构和参数对重建输入图像的难度的影响,并证明了任何输入到一个完全连接的层可以独立于其余的结构进行分析重建。最后,我们讨论了在实践中遇到的设置,并表明即使在几次迭代或几个图像上平均梯度也不能保护计算机视觉中联邦学习应用程序中的用户隐私。
The idea of federated learning is to collaboratively train a neural network on a server. Each user receives the current weights of the network and in turns sends parameter updates (gradients) based on local data. This protocol has been designed not only to train neural networks data-efficiently, but also to provide privacy benefits for users, as their input data remains on device and only parameter gradients are shared. But how secure is sharing parameter gradients? Previous attacks have provided a false sense of security, by succeeding only in contrived settings - even for a single image. However, by exploiting a magnitude-invariant loss along with optimization strategies based on adversarial attacks, we show that is is actually possible to faithfully reconstruct images at high resolution from the knowledge of their parameter gradients, and demonstrate that such a break of privacy is possible even for trained deep networks. We analyze the effects of architecture as well as parameters on the difficulty of reconstructing an input image and prove that any input to a fully connected layer can be reconstructed analytically independent of the remaining architecture. Finally we discuss settings encountered in practice and show that even averaging gradients over several iterations or several images does not protect the user's privacy in federated learning applications in computer vision.