Avaliação da Sensibilidade de Modelos a Ataques de Inversão de Gradiente no Aprendizado Federado
Resumo
O Aprendizado Federado (FL) permite o treinamento distribuído de modelos. O FL permanece vulnerável aos Ataques de Inversão de Gradiente (GIA), nos quais agentes maliciosos reconstroem dados dos clientes a partir dos gradientes compartilhados. Este trabalho avalia a sensibilidade de modelos locais aos GIA e investiga a eficácia da Privacidade Diferencial (DP) como estratégia de mitigação. Experimentos preliminares com o dataset LFW demonstram que camadas convolucionais são mais suscetíveis aos GIA, especialmente nas épocas iniciais do treinamento, e que níveis relativamente baixos de ruído são suficientes para degradar a qualidade das reconstruções.Referências
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L. (2016). Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS ’16, page 308–318, New York, NY, USA. Association for Computing Machinery.
Dwork, C. (2006). Differential privacy. In Bugliesi, M., Preneel, B., Sassone, V., and Wegener, I., editors, Automata, Languages and Programming, pages 1–12, Berlin, Heidelberg. Springer Berlin Heidelberg.
Leite, L., Santo, Y., Dalmazo, B., and Riker, A. (2024). Federated learning under attack: Improving gradient inversion for batch of images. In Anais do XXIV Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais, pages 794–800, Porto Alegre, RS, Brasil. SBC.
Mammen, P. M. (2021). Federated learning: Opportunities and challenges.
McMahan, B., Moore, E., Ramage, D., Hampson, S., and Arcas, B. A. y. (2017). Communication-Efficient Learning of Deep Networks from Decentralized Data. In Singh, A. and Zhu, J., editors, Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, volume 54 of Proceedings of Machine Learning Research, pages 1273–1282. PMLR.
McMahan, H. B., Andrew, G., Erlingsson, U., Chien, S., Mironov, I., Papernot, N., and Kairouz, P. (2019). A general approach to adding differential privacy to iterative training procedures.
Mo, F., Borovykh, A., Malekzadeh, M., Haddadi, H., and Demetriou, S. (2021). Layer-wise characterization of latent information leakage in federated learning.
Novak, R., Bahri, Y., Abolafia, D. A., Pennington, J., and Sohl-Dickstein, J. (2018). Sensitivity and generalization in neural networks: an empirical study.
Wang, Z., Peng, C., He, X., and Tan, W. (2023). Wasserstein distance-based deep leakage from gradients. Entropy, 25(5).
Zhao, B., Mopuri, K. R., and Bilen, H. (2020). idlg: Improved deep leakage from gradients. ArXiv, abs/2001.02610.
Zhu, L., Liu, Z., and Han, S. (2019). Deep leakage from gradients. In Advances in Neural Information Processing Systems, volume 32. Curran Associates, Inc.
Dwork, C. (2006). Differential privacy. In Bugliesi, M., Preneel, B., Sassone, V., and Wegener, I., editors, Automata, Languages and Programming, pages 1–12, Berlin, Heidelberg. Springer Berlin Heidelberg.
Leite, L., Santo, Y., Dalmazo, B., and Riker, A. (2024). Federated learning under attack: Improving gradient inversion for batch of images. In Anais do XXIV Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais, pages 794–800, Porto Alegre, RS, Brasil. SBC.
Mammen, P. M. (2021). Federated learning: Opportunities and challenges.
McMahan, B., Moore, E., Ramage, D., Hampson, S., and Arcas, B. A. y. (2017). Communication-Efficient Learning of Deep Networks from Decentralized Data. In Singh, A. and Zhu, J., editors, Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, volume 54 of Proceedings of Machine Learning Research, pages 1273–1282. PMLR.
McMahan, H. B., Andrew, G., Erlingsson, U., Chien, S., Mironov, I., Papernot, N., and Kairouz, P. (2019). A general approach to adding differential privacy to iterative training procedures.
Mo, F., Borovykh, A., Malekzadeh, M., Haddadi, H., and Demetriou, S. (2021). Layer-wise characterization of latent information leakage in federated learning.
Novak, R., Bahri, Y., Abolafia, D. A., Pennington, J., and Sohl-Dickstein, J. (2018). Sensitivity and generalization in neural networks: an empirical study.
Wang, Z., Peng, C., He, X., and Tan, W. (2023). Wasserstein distance-based deep leakage from gradients. Entropy, 25(5).
Zhao, B., Mopuri, K. R., and Bilen, H. (2020). idlg: Improved deep leakage from gradients. ArXiv, abs/2001.02610.
Zhu, L., Liu, Z., and Han, S. (2019). Deep leakage from gradients. In Advances in Neural Information Processing Systems, volume 32. Curran Associates, Inc.
Publicado
01/09/2026
Como Citar
BATISTA, João Pedro Camargo; MOTA, Vinicius F. S.; VILLAÇA, Rodolfo S..
Avaliação da Sensibilidade de Modelos a Ataques de Inversão de Gradiente no Aprendizado Federado. In: WORKSHOP DE TRABALHOS DE INICIAÇÃO CIENTÍFICA E DE GRADUAÇÃO EM ANDAMENTO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 798-803.
DOI: https://doi.org/10.5753/sbseg_estendido.2026.29883.
