Compromise Privacy in Large-Batch Federated Learning Via Model Poisoning

Shuaishuai Zhang,Jie Huang,Zeping Zhang,Chunyang Qi
DOI: https://doi.org/10.1016/j.ins.2023.119421
IF: 8.1
2023-01-01
Information Sciences
Abstract:Federated Learning (FL) is a distributed learning paradigm, in which users share their gradients instead of local data to preserve privacy. Previous works have shown that the server in FL can reveal user’s local data by inverting shared gradients. However, a large batchsize can defense against these attacks effectively by obfuscating gradients calculated on each data. In this paper, we propose a novel Gradient Inversion Attack which can compromise privacy in large-batch FL. Firstly, the server constructs malicious model parameters which can mitigate the confusion of gradients. Then users’ model parameters are tampered purposely by the server. From users’ shared gradients computed on malicious model parameters, the server can recover private local trainsets perfectly in large-batch FL. Experiments on CIFAR100 show that our method can recover 92%, 77% and 54% of the data points in a batch with batchsize 128, 256 and 512, respectively. Compared with previous works, our method has a higher performance and versatility.
What problem does this paper attempt to address?