Active Gradient Manipulation for Privacy Breaching in Vertical Federated Learning

Tre’ R. Jeter, Minh N. Vu, Raed Alharbi, Jung Taek Seo, My T. Thai · IEEE Transactions on Artificial Intelligence · 2025

Federated learning (FL) has emerged as a promising approach for privacy-preserving collaborative machine learning. Specifically, vertical FL (vFL) allows various devices in multi-agent systems to collectively train models on vertically partitioned data while safeguarding sensitive information. Recent research on vFL privacy analysis primarily explores passive settings where attackers adhere to the FL protocol. This perspective may underestimate the threats posed by vFL, as practical adversaries can deviate from the protocol to enhance their attack capabilities. In response, this work proposes two novelactivedata reconstruction attacks to compromise data privacy. Each attack induces gradient manipulation during the training phase to breach data privacy. Including an active inversion network (AIN), our first attack exploits a subset of known data in the training set to make passive parties train an auto-encoder (AE) to reconstruct their private data. The second attack introduces an active generative network (AGN) that relies only on the data distribution to train a conditional generative adversarial network (C-GAN) for private feature reconstruction. Our experiments demonstrate the effectiveness of both attacks in three real-world datasets: MNIST, CIFAR10, and USCensus. Additionally, we provide valuable insights and guidelines for enhancing the security of vFL systems through the application of calibrated noise via local differential privacy (LDP).

Read the paper · More papers on PaperTik