Inverting Gradient Attack Combined with GAN Network in Federated Learning of Face Recognition

Yiming Liu,Kejie Xu,Qiji Zheng,Jianhao Cui
DOI: https://doi.org/10.1109/ICFTIC54370.2021.9647073
2021-11-12
Abstract:In recent years, federated learning is often used as a means to protect data privacy and is widely used in face recognition and other privacy-related scenarios. In the past, it was generally believed that the gradient information uploaded to the server would not leak the original training data. However, it has been discovered that an efficient gradient leakage attack can restore the original data only through the gradient information. In the scene of face recognition, since the facial features contain complex information, the attack effect of this traditional gradient leakage attack is not ideal. This paper aims at the face recognition task in the federated learning scenario, for the first time through the constraints and round optimization of Face GAN, to indicate the best gradient descent direction for the training of the attack network model, so as to avoid falling into the local minimum, to improve the traditional gradient leakage attack. Experiments show that when the batch size=1 of the proposed scheme, after adding noise to the picture, our optimization scheme can significantly improve the anti-interference ability of the attack. The facial features recovered are clearer, the face is more natural, and the error with the original data is smaller, the error is reduced by 80% at most; when batch size>1, the improved attack scheme can prevent multiple pictures from being mixed on one picture, thereby recovering a larger number of pictures.
Computer Science
What problem does this paper attempt to address?