发表机构
Indian Institute of Technology Kharagpur(印度理工学院卡哈拉格普尔分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出路径积分替代模型扩展(PI-SME),通过高斯-勒让德求积近似梯度场路径积分,在CIFAR-100和FEMNIST上更忠实地重建联邦学习中的私有输入。
AI 中文摘要
联邦学习允许多个客户端共同训练一个共享模型,而无需将它们的私有数据发送到中央服务器。每个客户端仅共享一个模型更新,而这个更新对客户端的泄露应远少于其原始训练样本。这一前提正是保护客户端隐私的关键。梯度反演攻击直接挑战这一前提,试图从客户端共享的单个更新中重建其私有输入图像。在FedAvg下,客户端的更新累积了多个局部训练步骤,因此服务器只能看到隐藏权重轨迹的两个端点。最近的梯度反演攻击在这两个端点之间的路径上拟合一个替代模型,但它们仍然在单一点上读取其梯度。我们提出了路径积分替代模型扩展(PI-SME),它将累积更新视为梯度场的路径积分,并通过在可学习的贝塞尔路径上的多个节点处使用高斯-勒让德求积来近似它。在CIFAR-100和FEMNIST图像上,跨越一系列轨迹长度和类别受限批次,PI-SME在多个反演指标和匹配损失上比最强的替代基线更忠实地重建了私有输入。
英文摘要
Federated learning lets many clients train a shared model together without ever sending their private data to a central server. Each client shares only a model update, and this update should reveal far less about the client than its raw training examples would. This premise is what protects the privacy of the clients. Gradient inversion attacks challenge it directly by trying to reconstruct a client's private input images from the single update it shared. Under FedAvg, a client's update accumulates several local training steps, so the server sees only the two endpoints of a hidden weight trajectory. Recent gradient inversion attacks fit a surrogate model along the path between these two endpoints but they still read its gradient at a single point. We propose the Path-Integral Surrogate Model Extension (PI-SME) which treats the accumulated update as a path integral of the gradient field and approximates it by Gauss--Legendre quadrature over several nodes along a learnable Bézier path. On CIFAR-100 and FEMNIST images across a range of trajectory lengths and class-restricted batches PI-SME reconstructs the private inputs more faithfully than the strongest surrogate baseline on several inversion metrics and the matching loss.
Comments5 pages, 2 figures, 3 tables. Submitted to IEEE ICASSP 2027