Publication:
Unveiling Privacy Risks in Stochastic Neural Networks Training: Effective Image Reconstruction from Gradients
| cris.virtual.department | #PLACEHOLDER_PARENT_METADATA_VALUE# | |
| cris.virtual.department | #PLACEHOLDER_PARENT_METADATA_VALUE# | |
| cris.virtual.department | #PLACEHOLDER_PARENT_METADATA_VALUE# | |
| cris.virtual.orcid | 0000-0002-4639-2754 | |
| cris.virtual.orcid | 0000-0001-9300-5860 | |
| cris.virtual.orcid | 0000-0002-0845-6155 | |
| cris.virtualsource.department | 60f5f9f5-9e7c-4414-a3b2-138c34443e57 | |
| cris.virtualsource.department | 90f2bec3-f84d-4738-9103-ba2cd2f04cbc | |
| cris.virtualsource.department | ba7b5bee-bb97-47de-a137-fd8e1a08d07a | |
| cris.virtualsource.orcid | 60f5f9f5-9e7c-4414-a3b2-138c34443e57 | |
| cris.virtualsource.orcid | 90f2bec3-f84d-4738-9103-ba2cd2f04cbc | |
| cris.virtualsource.orcid | ba7b5bee-bb97-47de-a137-fd8e1a08d07a | |
| dc.contributor.author | Chen, Yiming | |
| dc.contributor.author | Yang, Xiangyu | |
| dc.contributor.author | Deligiannis, Nikos | |
| dc.date.accessioned | 2026-08-24T13:26:09Z | |
| dc.date.available | 2026-08-24T13:26:09Z | |
| dc.date.createdwos | 2024 | |
| dc.date.issued | 2025 | |
| dc.description.abstract | Federated Learning (FL) provides a framework for collaborative training of deep learning models while preserving data privacy by avoiding sharing the training data. However, recent studies have shown that a malicious server can reconstruct training data from the shared gradients of traditional neural networks (NNs) in FL, via Gradient Inversion Attacks (GIAs) that emulate the client’s training process. Contrary to earlier beliefs that Stochastic Neural Networks (SNNs) are immune to such attacks due to their stochastic nature (which makes the training process challenging to mimic), our findings reveal that SNNs are equally susceptible to GIAs as SNN gradients contain the information of stochastic components, allowing attackers to reconstruct and disclose those uncertain components. In this work, we play the role of an attacker and propose a novel attack method, named Inverting Stochasticity from Gradients (ISG), that can successfully reconstruct the training data by formulating the stochastic training process of SNNs as a variant of the traditional NN training process. Furthermore, to improve the fidelity of the reconstructed data, we introduce a feature constraint strategy. Extensive experiments validate the effectiveness of our GIA and suggest that perturbation-based defenses in forward propagation, such as using SNNs, fail to secure models against GIAs inherently. | |
| dc.description.wosFundingText | This work was supported in part by the Research Foundation - Flanders (FWO) through the Project under Grant G014718N and in part by the Flemish Government, under the "Onderzoeksprogramma Artificieele Intelligentie (AI) Vlaanderen" Programme. | |
| dc.identifier.doi | 10.1007/978-3-031-73404-5_23 | |
| dc.identifier.isbn | 978-3-031-73403-8 | |
| dc.identifier.issn | 0302-9743 | |
| dc.identifier.uri | https://imec-publications.be/handle/20.500.12860/60095 | |
| dc.language.iso | eng | |
| dc.provenance.editstepuser | greet.vanhoof@imec.be | |
| dc.publisher | SPRINGER INTERNATIONAL PUBLISHING AG | |
| dc.source.beginpage | 397 | |
| dc.source.conference | Computer Vision – ECCV 2024. 18th European Conference | |
| dc.source.conferencedate | 2024-09-28 | |
| dc.source.conferencelocation | Milano | |
| dc.source.endpage | 413 | |
| dc.source.journal | COMPUTER VISION - ECCV 2024, PT XXX | |
| dc.source.numberofpages | 17 | |
| dc.title | Unveiling Privacy Risks in Stochastic Neural Networks Training: Effective Image Reconstruction from Gradients | |
| dc.type | Proceedings paper | |
| dspace.entity.type | Publication | |
| imec.internal.crawledAt | 2026-07-14 | |
| imec.internal.source | crawler | |
| imec.internal.wosCreatedAt | 2026-07-14 | |
| Files | ||
| Publication available in collections: |