Conditional GAN-Based Gradient Recovery Attack for Differentially Private Deep Image Processing
Lihua Yin, Simin Wang, Zhe Sun, Zhi Yang, Y. P. Zou, Nan Wei, Yuanyuan He · 2023
It has been demonstrated that gradients of deep learning models, especially image processing models, can be exploited to memorize sensitive information from training data, rendering them vulnerable to gradient inversion attacks. Differential privacy, a provably secure privacy-preserving technique, has been widely adopted to protect gradients of deep learning models. In this paper, we propose a gradient recovery attack against differential privacy-preserving models. Adversaries can gather a small set of differential privacy perturbed and original gradients and leverage a cGAN network to train a gradient recovery model, which can recover the perturbed gradient to an approximately original state. Subsequently, the recovered gradient can be targeted by gradient inversion attacks, leading to further privacy leakage from the training data. Our experiments demonstrate that the proposed gradient recovery attack achieves promising results when using commonly used differential privacy budgets (from 1 to 7). When the privacy budget is 7, the recovered gradient and the original gradient have a similarity of 94-99% in gradient inversion attack.