volume 11 issue 17 pages 28774-28786

Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation

Yu Sun 1
Zheng Liu 1
Jian Cui 1
Jianhua Liu 1
Kailang Ma 1
Jianwei Liu 1
Publication typeJournal Article
Publication date2024-09-01
scimago Q1
wos Q1
SJR2.483
CiteScore16.3
Impact factor8.9
ISSN23274662, 23722541
Abstract
As a privacy-preserving enhancement to the Federated Learning (FL) framework, Secure Aggregation (SA) enables multiparty summation without any party needing to reveal their updates to the aggregator in Internet of Things applications. However, conventional threat model underestimates the potential inversion attacks on aggregated gradients from an honest-but-curious client, due to the considering information loss caused by SA. This study for the first time, demonstrates the gradient inversion attack against SA schemes in which gradients are quantized and aggregated. Then an enhanced gradient inversion from client side is proposed to address two roadblocks caused by SA, i.e., aggregation information loss and quantization rounding error. To countermeasure the information loss, we utilize class-wise representation matching to achieve category-level decomposition. This relies on a prior restoration of the class-wise representations and instance-wise labels, whose numerical accuracy is cyclically calibrated through prior-based offset estimation. Since cryptographic operators involved in SA schemes usually operates in the integer domain, gradient quantization is introduced. Regarding the rounding errors from gradient quantization, quantization-aware gradient matching is presented to align with a more precise optimization objective. Extensive experiments demonstrate that a semi-honest client is sufficient to infer sensitive data from the aggregated gradients after even 8-bit quantization. Moreover, a defense scheme based on 1-bit gradient quantization is proposed. The new attack from client side in SA-based FL urges the community to take necessary defensive measures.
Found 
Found 

Top-30

Journals

1
2
3
IEEE Internet of Things Journal
3 publications, 60%
IEEE Open Journal of the Communications Society
1 publication, 20%
Business and Information Systems Engineering
1 publication, 20%
1
2
3

Publishers

1
2
3
4
Institute of Electrical and Electronics Engineers (IEEE)
4 publications, 80%
Springer Nature
1 publication, 20%
1
2
3
4
  • We do not take into account publications without a DOI.
  • Statistics recalculated weekly.

Are you a researcher?

Create a profile to get free access to personal recommendations for colleagues and new articles.
Metrics
5
Share
Cite this
GOST |
Cite this
GOST Copy
Sun Yu. et al. Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation // IEEE Internet of Things Journal. 2024. Vol. 11. No. 17. pp. 28774-28786.
GOST all authors (up to 50) Copy
Sun Yu., Liu Z., Cui J., Liu J., Ma K., Liu J. Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation // IEEE Internet of Things Journal. 2024. Vol. 11. No. 17. pp. 28774-28786.
RIS |
Cite this
RIS Copy
TY - JOUR
DO - 10.1109/jiot.2024.3405939
UR - https://ieeexplore.ieee.org/document/10540055/
TI - Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation
T2 - IEEE Internet of Things Journal
AU - Sun, Yu
AU - Liu, Zheng
AU - Cui, Jian
AU - Liu, Jianhua
AU - Ma, Kailang
AU - Liu, Jianwei
PY - 2024
DA - 2024/09/01
PB - Institute of Electrical and Electronics Engineers (IEEE)
SP - 28774-28786
IS - 17
VL - 11
SN - 2327-4662
SN - 2372-2541
ER -
BibTex |
Cite this
BibTex (up to 50 authors) Copy
@article{2024_Sun,
author = {Yu Sun and Zheng Liu and Jian Cui and Jianhua Liu and Kailang Ma and Jianwei Liu},
title = {Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation},
journal = {IEEE Internet of Things Journal},
year = {2024},
volume = {11},
publisher = {Institute of Electrical and Electronics Engineers (IEEE)},
month = {sep},
url = {https://ieeexplore.ieee.org/document/10540055/},
number = {17},
pages = {28774--28786},
doi = {10.1109/jiot.2024.3405939}
}
MLA
Cite this
MLA Copy
Sun, Yu., et al. “Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation.” IEEE Internet of Things Journal, vol. 11, no. 17, Sep. 2024, pp. 28774-28786. https://ieeexplore.ieee.org/document/10540055/.