Song Y, Wang Z, Zuazua E (2026)
Publication Type: Journal article
Publication year: 2026
DOI: 10.1109/TBDATA.2026.3695416
Federated learning (FL) is a distributed learning paradigm that enables multiple clients to collaboratively train a machine learning model without sharing private data. Although FL is normally regarded as privacy-preserving by design, recent data reconstruction attacks demonstrate that adversaries can recover clients' training data from the shared model updates. However, existing attack methods frequently fail in the widely used Federated Averaging (FedAvg) setting, where clients only transmit model parameters after executing multiple local training steps. To overcome this limitation, we propose an interpolation-based approximation method that renders attacks on FedAvg feasible by effectively estimating the intermediate model updates generated during local training. Furthermore, we design a layer-wise weighted loss function to enhance reconstruction quality. Specifically, weights are assigned to different layers based on the neural network architecture and are systematically tuned via Bayesian optimization. Experimental results demonstrate that the proposed approximate and weighted attack method outperforms existing state-of-the-art approaches, yielding substantial improvements across multiple image reconstruction metrics.
APA:
Song, Y., Wang, Z., & Zuazua, E. (2026). Approximate and Weighted Data Reconstruction Attack in Federated Learning. IEEE Transactions on Big Data. https://doi.org/10.1109/TBDATA.2026.3695416
MLA:
Song, Yongcun, Ziqi Wang, and Enrique Zuazua. "Approximate and Weighted Data Reconstruction Attack in Federated Learning." IEEE Transactions on Big Data (2026).
BibTeX: Download