🤖 AI Summary
This study addresses the challenge of reconstructing private data from accumulated updates in multi-step gradient inversion attacks within federated learning. To this end, we propose a path integral surrogate model that interprets FedAvg accumulated updates as path integrals over a gradient field. By leveraging Gaussian-Legendre quadrature to approximate multiple nodes along learnable Bézier curves, this approach pioneers a path integral perspective to transcend the limitations of single-point gradient extraction, thereby enabling efficient privacy reconstruction. Extensive experiments on the CIFAR-100 and FEMNIST datasets demonstrate that the proposed method consistently outperforms state-of-the-art baselines across all evaluation metrics. It significantly enhances reconstruction fidelity, effectively exposing critical privacy vulnerabilities inherent in federated learning systems.
📝 Abstract
Federated learning lets many clients train a shared model together without ever sending their private data to a central server. Each client shares only a model update, and this update should reveal far less about the client than its raw training examples would. This premise is what protects the privacy of the clients. Gradient inversion attacks challenge it directly by trying to reconstruct a client's private input images from the single update it shared. Under FedAvg, a client's update accumulates several local training steps, so the server sees only the two endpoints of a hidden weight trajectory. Recent gradient inversion attacks fit a surrogate model along the path between these two endpoints but they still read its gradient at a single point. We propose the Path-Integral Surrogate Model Extension (PI-SME) which treats the accumulated update as a path integral of the gradient field and approximates it by Gauss--Legendre quadrature over several nodes along a learnable Bézier path. On CIFAR-100 and FEMNIST images across a range of trajectory lengths and class-restricted batches PI-SME reconstructs the private inputs more faithfully than the strongest surrogate baseline on several inversion metrics and the matching loss.