Do Gradient Inversion Attacks Make Federated Learning Unsafe?
arXiv:2202.06924 · doi:10.1109/TMI.2023.3239391
Abstract
Federated learning (FL) allows the collaborative training of AI models without needing to share raw data. This capability makes it especially interesting for healthcare applications where patient and data privacy is of utmost concern. However, recent works on the inversion of deep neural networks from model gradients raised concerns about the security of FL in preventing the leakage of training data. In this work, we show that these attacks presented in the literature are impractical in FL use-cases where the clients' training involves updating the Batch Normalization (BN) statistics and provide a new baseline attack that works for such scenarios. Furthermore, we present new ways to measure and visualize potential data leakage in FL. Our work is a step towards establishing reproducible methods of measuring data leakage in FL and could help determine the optimal tradeoffs between privacy-preserving techniques, such as differential privacy, and model accuracy based on quantifiable metrics. Code is available at https://nvidia.github.io/NVFlare/research/quantifying-data-leakage.
Revised version; Accepted to IEEE Transactions on Medical Imaging; Improved and reformatted version of https://www.researchsquare.com/article/rs-1147182/v2; Added NVFlare reference
References in corpus (6)
- Batch Normalization: Accelerating Deep Network Training by Reducing Internal Covariate Shift
- FedBN: Federated Learning on Non-IID Features via Local Batch Normalization
- Federated Learning and Differential Privacy: Software tools analysis, the Sherpa.ai FL framework and methodological guidelines for preserving data privacy
- Local Differential Privacy and Its Applications: A Comprehensive Survey
- NVIDIA FLARE: Federated Learning from Simulation to Real-World
- Local and Central Differential Privacy for Robustness and Privacy in Federated Learning
Cited by in corpus (9)
- The Federation Strikes Back: A Survey of Federated Learning Privacy Attacks, Defenses, Applications, and Policy Landscape
- Private, fair and accurate: Training large-scale, privacy-preserving AI models in medical imaging
- Personalized and privacy-preserving federated heterogeneous medical image analysis with PPPML-HMI
- Threats and Defenses in Federated Learning Life Cycle: A Comprehensive Survey and Challenges
- Differential privacy for medical deep learning: methods, tradeoffs, and deployment implications
- Federated brain tumor segmentation: an extensive benchmark
- Decentralized Personalization for Federated Medical Image Segmentation via Gossip Contrastive Mutual Learning
- Differential privacy enables fair and accurate AI-based analysis of speech disorders while protecting patient data
- Understanding Deep Gradient Leakage via Inversion Influence Functions