Pith. sign in

REVIEW 1 cited by

Combining Stochastic Defenses to Resist Gradient Inversion: An Ablation Study

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2208.04767 v2 pith:M2TQ5GNV submitted 2022-08-09 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords privacygradientdefensedefensesstochasticattacksablationattacker
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Gradient Inversion (GI) attacks are a ubiquitous threat in Federated Learning (FL) as they exploit gradient leakage to reconstruct supposedly private training data. Common defense mechanisms such as Differential Privacy (DP) or stochastic Privacy Modules (PMs) introduce randomness during gradient computation to prevent such attacks. However, we pose that if an attacker effectively mimics a client's stochastic gradient computation, the attacker can circumvent the defense and reconstruct clients' private training data. This paper introduces several targeted GI attacks that leverage this principle to bypass common defense mechanisms. As a result, we demonstrate that no individual defense provides sufficient privacy protection. To address this issue, we propose to combine multiple defenses. We conduct an extensive ablation study to evaluate the influence of various combinations of defenses on privacy protection and model utility. We observe that only the combination of DP and a stochastic PM was sufficient to decrease the Attack Success Rate (ASR) from 100% to 0%, thus preserving privacy. Moreover, we found that this combination of defenses consistently achieves the best trade-off between privacy and model utility.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Label Leakage in Federated Inertial-based Human Activity Recognition

    cs.LG 2025-05 conditional novelty 6.0 of 10

    Gradient-based label leakage attacks recover activity class labels from federated HAR updates with high accuracy, especially under sequential sampling, and standard local privacy defenses provide only partial protection.

Pith tools