Gradient Inversion Attack via Image-Correction-Penalty-Based Over-Parameterized Regression Network in Federated Learning
Bin Xu, Qing Wen, Longgang Cheng, Xiaoxuan Hu, Tian Li, Yanfei Sun · IEEE Internet of Things Journal · 2025
While Federated Learning is intended to safeguard data privacy, it is confronted with the problem of gradient leakage, which empowers attackers to execute gradient inversion attacks and retrieve the original data through the shared gradient information. Existing gradient inversion attack methods can achieve good results when handling small batches of low-resolution images. However, when dealing with large batches of high-resolution images, problems such as gradient ambiguity and model instability will occur, resulting in a significant decrease in the recovery performance. We propose a novel Image-correction-penalty based Over-parameterized Regression Network (IORN). IORN breaks through the limitations of existing methods with its unique design. The Adaptive Over-parameterized Network in IORN can dynamically adjust its structure, thereby enhancing the network’s ability to capture complex data distributions. This enables it to better handle the complexity of large batches of high-resolution images and improves the model’s reconstruction ability for such images. Meanwhile, the designed image correction penalty term restricts the difference between the generated images and the average image. This not only improves the stability of the optimization process but also reduces the convergence deviation. Experimental results demonstrate that IORN significantly improves the resolution and fidelity of reconstructed images during gradient inversion attacks on the MNIST, CIFAR-100, and LFW datasets, especially showing outstanding performance when dealing with large batches of complex images.