<p>The gradient inversion attack presents a significant threat to the data privacy in federated learning, enabling malicious adversaries to reconstruct private training data from gradients. Among the various protection strategies, data augmentation-based approaches have emerged as particularly promising. These methods can be seamlessly incorporated into existing federated learning frameworks, offering both efficiency and minimal impact on model accuracy. In this paper, we propose a novel data protection technique that leverages data augmentation methods, specifically CutMix and SaliencyMix. These techniques work by mixing images, which allows for more efficient utilization of training pixels. This, in turn, aids the model in learning more robust and meaningful feature representations, thereby enhancing both the model performance and its resilience to adversarial attacks. To further strengthen data privacy, we integrate these data augmentation methods with data pruning techniques. Our empirical results demonstrate that the proposed approach not only improves the accuracy of federated learning models but also reduces the quality of reconstructed images, offering a higher level of data privacy protection.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A gradient inversion attack defense method based on data augmentation

  • Yingge Li,
  • Xianlin Wu,
  • Yuwen Chen,
  • Haiyang Yu,
  • Zhen Yang

摘要

The gradient inversion attack presents a significant threat to the data privacy in federated learning, enabling malicious adversaries to reconstruct private training data from gradients. Among the various protection strategies, data augmentation-based approaches have emerged as particularly promising. These methods can be seamlessly incorporated into existing federated learning frameworks, offering both efficiency and minimal impact on model accuracy. In this paper, we propose a novel data protection technique that leverages data augmentation methods, specifically CutMix and SaliencyMix. These techniques work by mixing images, which allows for more efficient utilization of training pixels. This, in turn, aids the model in learning more robust and meaningful feature representations, thereby enhancing both the model performance and its resilience to adversarial attacks. To further strengthen data privacy, we integrate these data augmentation methods with data pruning techniques. Our empirical results demonstrate that the proposed approach not only improves the accuracy of federated learning models but also reduces the quality of reconstructed images, offering a higher level of data privacy protection.