Gradient inversion attacks threaten client privacy in federated learning by reconstructing training samples from clients' shared gradients. Gradients aggregate contributions from multiple records and existing attacks may fail to disentangle them, yielding incorrect reconstructions with no intrinsic way to certify success. In vision and language, attackers may fall back on human inspection to judge reconstruction plausibility, but this is far less feasible for numerical tabular records, fueling the impression that tabular data is less vulnerable. We challenge this perception by proposing a verifiable gradient inversion attack (VGIA) that provides an explicit certificate of correctness for reconstructed samples. Our method adopts a geometric view of ReLU leakage: the activation boundary of a fully connected layer defines a hyperplane in input space. VGIA introduces an algebraic, subspace-based verification test that detects when a hyperplane-delimited region contains exactly one record. Once isolation is certified, VGIA recovers the corresponding feature vector analytically and reconstructs the target via a lightweight optimization step. Experiments on tabular benchmarks with large batch sizes demonstrate exact record and target recovery in regimes where existing state-of-the-art attacks either fail or cannot assess reconstruction fidelity. Compared to prior geometric approaches, VGIA allocates hyperplane queries more effectively, yielding faster reconstructions with fewer attack rounds.
翻译:梯度反转攻击通过从客户端共享的梯度中重建训练样本,威胁联邦学习中的客户隐私。梯度聚合了多个记录的贡献,现有攻击可能无法从中分离出单个记录,导致错误的重建,且没有内在方式验证其成功与否。在视觉和语言领域,攻击者可依靠人工检查判断重建的合理性,但对于数值表格数据而言,这远不可行,从而强化了表格数据不易受攻击的印象。我们通过提出一种可验证的梯度反转攻击(VGIA)挑战这一认知,该攻击为重建样本提供明确的正确性认证。我们的方法采用ReLU泄漏的几何视角:全连接层的激活边界在输入空间中定义一个超平面。VGIA引入一种基于子空间代数的验证测试,用于检测由超平面界定的区域是否恰好包含一个记录。一旦隔离性被认证,VGIA解析地恢复对应的特征向量,并通过轻量级优化步骤重建目标。在大批量设置下的表格基准实验表明,在现有最先进攻击要么失败、要么无法评估重建保真度的场景中,VGIA实现了精确的记录和目标恢复。与先前的几何方法相比,VGIA更有效地分配超平面查询,从而以更少的攻击轮次实现更快的重建。