Gradient Leakage Defense in Federated Learning Using Gradient Perturbation-based Dynamic Clipping

Changsong Yang, Sirui Hang, Yong Ding, Chunhai Li, Hai Liang, Zhen Liu · 2024

Federated Learning, as a distributed learning model, enables multiple clients to collaboratively train models while preserving data privacy. However, recent studies have highlighted a potential drawback: sharing gradient information could unintentionally lead to the exposure of private training data, allowing attackers to reconstruct this data from the shared gradients. To defend against this threat while maintaining high model accuracy, we propose a defensive method called Gradient Perturbation-based Dynamic Clipping (GPDC). This method mitigates the risk of gradient information leakage by introducing minor perturbations to the shared gradients and employing dynamic clipping techniques to preserve model accuracy. It combines two approaches: gradient perturbation and segmented clipping. Clients use an adaptive mechanism to dynamically trim gradients. After trimming, noise scales are adaptively added, with the noise determined by the clipping threshold and gradient changes. The effectiveness of the proposed defensive strategy was evaluated through experiments on the MNIST and CIFAR10 datasets. The results reveal that the GPDC method successfully resists DLG attacks while maintaining high model performance.

Read the paper · More papers on PaperTik