Publication:

Unveiling Privacy Risks in Stochastic Neural Networks Training: Effective Image Reconstruction from Gradients

 
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.department#PLACEHOLDER_PARENT_METADATA_VALUE#
cris.virtual.orcid0000-0002-4639-2754
cris.virtual.orcid0000-0001-9300-5860
cris.virtual.orcid0000-0002-0845-6155
cris.virtualsource.department60f5f9f5-9e7c-4414-a3b2-138c34443e57
cris.virtualsource.department90f2bec3-f84d-4738-9103-ba2cd2f04cbc
cris.virtualsource.departmentba7b5bee-bb97-47de-a137-fd8e1a08d07a
cris.virtualsource.orcid60f5f9f5-9e7c-4414-a3b2-138c34443e57
cris.virtualsource.orcid90f2bec3-f84d-4738-9103-ba2cd2f04cbc
cris.virtualsource.orcidba7b5bee-bb97-47de-a137-fd8e1a08d07a
dc.contributor.authorChen, Yiming
dc.contributor.authorYang, Xiangyu
dc.contributor.authorDeligiannis, Nikos
dc.date.accessioned2026-08-24T13:26:09Z
dc.date.available2026-08-24T13:26:09Z
dc.date.createdwos2024
dc.date.issued2025
dc.description.abstractFederated Learning (FL) provides a framework for collaborative training of deep learning models while preserving data privacy by avoiding sharing the training data. However, recent studies have shown that a malicious server can reconstruct training data from the shared gradients of traditional neural networks (NNs) in FL, via Gradient Inversion Attacks (GIAs) that emulate the client’s training process. Contrary to earlier beliefs that Stochastic Neural Networks (SNNs) are immune to such attacks due to their stochastic nature (which makes the training process challenging to mimic), our findings reveal that SNNs are equally susceptible to GIAs as SNN gradients contain the information of stochastic components, allowing attackers to reconstruct and disclose those uncertain components. In this work, we play the role of an attacker and propose a novel attack method, named Inverting Stochasticity from Gradients (ISG), that can successfully reconstruct the training data by formulating the stochastic training process of SNNs as a variant of the traditional NN training process. Furthermore, to improve the fidelity of the reconstructed data, we introduce a feature constraint strategy. Extensive experiments validate the effectiveness of our GIA and suggest that perturbation-based defenses in forward propagation, such as using SNNs, fail to secure models against GIAs inherently.
dc.description.wosFundingTextThis work was supported in part by the Research Foundation - Flanders (FWO) through the Project under Grant G014718N and in part by the Flemish Government, under the "Onderzoeksprogramma Artificieele Intelligentie (AI) Vlaanderen" Programme.
dc.identifier.doi10.1007/978-3-031-73404-5_23
dc.identifier.isbn978-3-031-73403-8
dc.identifier.issn0302-9743
dc.identifier.urihttps://imec-publications.be/handle/20.500.12860/60095
dc.language.isoeng
dc.provenance.editstepusergreet.vanhoof@imec.be
dc.publisherSPRINGER INTERNATIONAL PUBLISHING AG
dc.source.beginpage397
dc.source.conferenceComputer Vision – ECCV 2024. 18th European Conference
dc.source.conferencedate2024-09-28
dc.source.conferencelocationMilano
dc.source.endpage413
dc.source.journalCOMPUTER VISION - ECCV 2024, PT XXX
dc.source.numberofpages17
dc.title

Unveiling Privacy Risks in Stochastic Neural Networks Training: Effective Image Reconstruction from Gradients

dc.typeProceedings paper
dspace.entity.typePublication
imec.internal.crawledAt2026-07-14
imec.internal.sourcecrawler
imec.internal.wosCreatedAt2026-07-14
Files
Publication available in collections: