Enabling Gradient Inversion Attack Against SplitFed Learning via L 2 Norm Amplification

Jianan Zhao, Wenjuan Tang, Kuan Zhang, Hongbo Jiang · IEEE Transactions on Information Forensics and Security · 2025

SplitFed Learning (SFL) represents a compelling distributed learning paradigm tailored for resource-constrained edge computing scenarios, wherein the privacy threat posed by Gradient Inversion Attacks (GIA) remains challenging. The unique architecture of SFL restricts the fed server’s access only to the client-side model’sdeficient gradients, which lack essential information about the original data. This absence of complete gradient information hinders traditional GIA methods, which rely on complete gradient information for effective data reconstruction, thereby significantly diminishing their effectiveness in the SFL context. In this paper, we propose a novel attack against SFL calledDeficient Gradient-based Inversion Attack(DGIA), which reconstructs original training data by artificially amplifying the ℓ2norm of deficient gradients. Through extensive evaluation of how GIA performance varies with different gradient magnitudes, we observe a definitive correlation between the gradient ℓ2norm and attack performance. Based on this correlation, we further optimize DGIA to identify the optimal gradient amplification scale that maximizes the information encoded in deficient gradients. This compensates for the restricted access to complete gradients and enhances the attack performance. We conduct extensive experiments to demonstrate DGIA’s performance across various SFL scenarios compared with other GIA schemes and show attack efficacy under general defenses.

Read the paper · More papers on PaperTik