• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

联邦学习中针对梯度反转攻击的影子防御

Shadow defense against gradient inversion attack in federated learning.

作者信息

Jiang Le, Ma Liyan, Yang Guang

机构信息

Bioengineering Department and Imperial-X, Imperial College London, London W12 7SL, UK.

School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China.

出版信息

Med Image Anal. 2025 Oct;105:103673. doi: 10.1016/j.media.2025.103673. Epub 2025 Jun 21.

DOI:10.1016/j.media.2025.103673
PMID:40570807
Abstract

Federated learning (FL) has emerged as a transformative framework for privacy-preserving distributed training, allowing clients to collaboratively train a global model without sharing their local data. This is especially crucial in sensitive fields like healthcare, where protecting patient data is paramount. However, privacy leakage remains a critical challenge, as the communication of model updates can be exploited by potential adversaries. Gradient inversion attacks (GIAs), for instance, allow adversaries to approximate the gradients used for training and reconstruct training images, thus stealing patient privacy. Existing defense mechanisms obscure gradients, yet lack a nuanced understanding of which gradients or types of image information are most vulnerable to such attacks. These indiscriminate calibrated perturbations result in either excessive privacy protection degrading model accuracy, or insufficient one failing to safeguard sensitive information. Therefore, we introduce a framework that addresses these challenges by leveraging a shadow model with interpretability for identifying sensitive areas. This enables a more targeted and sample-specific noise injection. Specially, our defensive strategy achieves discrepancies of 3.73 in PSNR and 0.2 in SSIM compared to the circumstance without defense on the ChestXRay dataset, and 2.78 in PSNR and 0.166 in the EyePACS dataset. Moreover, it minimizes adverse effects on model performance, with less than 1% F1 reduction compared to SOTA methods. Our extensive experiments, conducted across diverse types of medical images, validate the generalization of the proposed framework. The stable defense improvements for FedAvg are consistently over 1.5% times in LPIPS and SSIM. It also offers a universal defense against various GIA types, especially for these sensitive areas in images.

摘要

联邦学习(FL)已成为一种用于隐私保护分布式训练的变革性框架,允许客户端在不共享本地数据的情况下协作训练全局模型。这在医疗保健等敏感领域尤为关键,因为保护患者数据至关重要。然而,隐私泄露仍然是一个关键挑战,因为模型更新的通信可能会被潜在对手利用。例如,梯度反转攻击(GIA)允许对手近似用于训练的梯度并重建训练图像,从而窃取患者隐私。现有的防御机制会模糊梯度,但对哪些梯度或图像信息类型最容易受到此类攻击缺乏细致的理解。这些不加区分的校准扰动要么导致过度的隐私保护降低模型准确性,要么导致保护不足无法保护敏感信息。因此,我们引入了一个框架,通过利用具有可解释性的影子模型来识别敏感区域,从而应对这些挑战。这使得能够进行更有针对性的、针对特定样本的噪声注入。具体而言,与在ChestXRay数据集上无防御的情况相比,我们的防御策略在PSNR方面实现了3.73的差异,在SSIM方面实现了0.2的差异;在EyePACS数据集上,PSNR方面为2.78,SSIM方面为0.166。此外,它将对模型性能的不利影响降至最低,与最优方法相比,F1降低不到1%。我们在各种类型的医学图像上进行的广泛实验验证了所提出框架的通用性。对于FedAvg的稳定防御改进在LPIPS和SSIM方面始终超过1.5%。它还为各种类型的GIA提供了通用防御,特别是针对图像中的这些敏感区域。

相似文献

1
Shadow defense against gradient inversion attack in federated learning.联邦学习中针对梯度反转攻击的影子防御
Med Image Anal. 2025 Oct;105:103673. doi: 10.1016/j.media.2025.103673. Epub 2025 Jun 21.
2
Prescription of Controlled Substances: Benefits and Risks管制药品的处方:益处与风险
3
Minimal data poisoning attack in federated learning for medical image classification: An attacker perspective.医学图像分类联邦学习中的最小数据中毒攻击:攻击者视角
Artif Intell Med. 2025 Jan;159:103024. doi: 10.1016/j.artmed.2024.103024. Epub 2024 Nov 26.
4
SpyShield: a Spyfall inspired defense mechanism against poisoning attacks in federated learning.SpyShield:一种受Spyfall启发的针对联邦学习中毒攻击的防御机制。
Sci Rep. 2025 Aug 26;15(1):31374. doi: 10.1038/s41598-025-16158-3.
5
A novel federated learning framework for medical imaging: Resource-efficient approach combining PCA with early stopping.一种用于医学成像的新型联邦学习框架:将主成分分析与提前停止相结合的资源高效方法。
Med Phys. 2025 Aug;52(8):e18064. doi: 10.1002/mp.18064.
6
Healthcare workers' informal uses of mobile phones and other mobile devices to support their work: a qualitative evidence synthesis.医护人员非正规使用手机和其他移动设备来支持工作:定性证据综合评价。
Cochrane Database Syst Rev. 2024 Aug 27;8(8):CD015705. doi: 10.1002/14651858.CD015705.pub2.
7
Identifying significant features in adversarial attack detection framework using federated learning empowered medical IoT network security.利用联邦学习赋能的医疗物联网网络安全在对抗攻击检测框架中识别显著特征。
Sci Rep. 2025 Aug 26;15(1):31485. doi: 10.1038/s41598-025-14913-0.
8
Short-Term Memory Impairment短期记忆障碍
9
Aspects of Genetic Diversity, Host Specificity and Public Health Significance of Single-Celled Intestinal Parasites Commonly Observed in Humans and Mostly Referred to as 'Non-Pathogenic'.人类常见且大多被称为“非致病性”的单细胞肠道寄生虫的遗传多样性、宿主特异性及公共卫生意义
APMIS. 2025 Sep;133(9):e70036. doi: 10.1111/apm.70036.
10
Privacy-Preserving Glycemic Management in Type 1 Diabetes: Development and Validation of a Multiobjective Federated Reinforcement Learning Framework.1型糖尿病中保护隐私的血糖管理:多目标联邦强化学习框架的开发与验证
JMIR Diabetes. 2025 Jul 4;10:e72874. doi: 10.2196/72874.