Approximate and Weighted Data Reconstruction Attack in Federated Learning

Song Y, Wang Z, Zuazua E (2026)


Publication Type: Journal article

Publication year: 2026

Journal

DOI: 10.1109/TBDATA.2026.3695416

Abstract

Federated learning (FL) is a distributed learning paradigm that enables multiple clients to collaboratively train a machine learning model without sharing private data. Although FL is normally regarded as privacy-preserving by design, recent data reconstruction attacks demonstrate that adversaries can recover clients' training data from the shared model updates. However, existing attack methods frequently fail in the widely used Federated Averaging (FedAvg) setting, where clients only transmit model parameters after executing multiple local training steps. To overcome this limitation, we propose an interpolation-based approximation method that renders attacks on FedAvg feasible by effectively estimating the intermediate model updates generated during local training. Furthermore, we design a layer-wise weighted loss function to enhance reconstruction quality. Specifically, weights are assigned to different layers based on the neural network architecture and are systematically tuned via Bayesian optimization. Experimental results demonstrate that the proposed approximate and weighted attack method outperforms existing state-of-the-art approaches, yielding substantial improvements across multiple image reconstruction metrics.

Authors with CRIS profile

Involved external institutions

How to cite

APA:

Song, Y., Wang, Z., & Zuazua, E. (2026). Approximate and Weighted Data Reconstruction Attack in Federated Learning. IEEE Transactions on Big Data. https://doi.org/10.1109/TBDATA.2026.3695416

MLA:

Song, Yongcun, Ziqi Wang, and Enrique Zuazua. "Approximate and Weighted Data Reconstruction Attack in Federated Learning." IEEE Transactions on Big Data (2026).

BibTeX: Download