Exploiting Subcontact Gradient Leakage Through SGAN-Based Data Reconstruction: Uncovering a New Adversarial Threat in Asynchronous Federated Learning Systems

J. Jaffer Basha, Mohan Annamalai, Periyasami Selvaraju · 2025

In the era of ubiquitous computing and collaborative learning paradigms, A potent method for training data mining models over numerous dispersed devices is federated training, or FL. However, privacy concerns have surged due to potential information leakage from shared model updates. Here, we recommend a narrative Subcontact Generative Adversarial Network (SGAN) based Reconstructive Attack (SGAN-RA) framework that operates under an Asynchronous Federated Learning (AFL) setting. Our proposed attack demonstrates the feasibility of reconstructing sensitive client data from gradient updates without direct access to the original data. SGAN-RA achieves an average attack reconstruction accuracy of 89.7%, significantly outperforming Active mGAN-AI (84.3%), Passive mGAN-AI (80.1%), and typical GAN attacks (73.2%). It also delivers higher perceptual fidelity, evidenced by PSNR of 33.2 and SSIM of 0.91, indicating sharper and more realistic reconstructions. We introduce a defense mechanism based on Differential Update Masking (DUM) to mitigate this threat. Experimental results on a synthetic dataset of 20,000 samples validate the effectiveness of SGAN-RA in exposing vulnerabilities in AFL systems while also offering a viable pathway to enhancing federated privacy.

Read the paper · More papers on PaperTik