iDLG: Improved Deep Leakage from Gradients

01/08/2020
by   Bo Zhao, et al.
0

It is widely believed that sharing gradients will not leak private training data in distributed learning systems such as Collaborative Learning and Federated Learning, etc. Recently, Zhu et al. presented an approach which shows the possibility to obtain private training data from the publicly shared gradients. In their Deep Leakage from Gradient (DLG) method, they synthesize the dummy data and corresponding labels with the supervision of shared gradients. However, DLG has difficulty in convergence and discovering the ground-truth labels consistently. In this paper, we find that sharing gradients definitely leaks the ground-truth labels. We propose a simple but reliable approach to extract accurate data from the gradients. Particularly, our approach can certainly extract the ground-truth labels as opposed to DLG, hence we name it Improved DLG (iDLG). Our approach is valid for any differentiable model trained with cross-entropy loss over one-hot labels. We mathematically illustrate how our method can extract ground-truth labels from the gradients and empirically demonstrate the advantages over DLG.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/19/2021

User Label Leakage from Gradients in Federated Learning

Federated learning enables multiple users to build a joint model by shar...
research
06/21/2019

Deep Leakage from Gradients

Exchanging gradients is a widely used method in modern multi-node machin...
research
08/25/2021

Dropout against Deep Leakage from Gradients

As the scale and size of the data increases significantly nowadays, fede...
research
06/16/2019

Floors are Flat: Leveraging Semantics for Real-Time Surface Normal Prediction

We propose 4 insights that help to significantly improve the performance...
research
04/06/2023

Probing the Purview of Neural Networks via Gradient Analysis

We analyze the data-dependent capacity of neural networks and assess ano...
research
02/17/2021

Label Leakage and Protection in Two-party Split Learning

In vertical federated learning, two-party split learning has become an i...
research
01/07/2020

The Ground Truth Trade-Off in Wearable Sensing Studies

Perez et al's study using the Apple Watch to identify atrial fibrillatio...

Please sign up or login with your details

Forgot password? Click here to reset