{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T04:45:34Z","timestamp":1780634734938,"version":"3.54.1"},"reference-count":36,"publisher":"MDPI AG","issue":"19","license":[{"start":{"date-parts":[[2022,9,21]],"date-time":"2022-09-21T00:00:00Z","timestamp":1663718400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Hainan Province Science and Technology Special Fund","award":["ZDYF2022SHFZ026"],"award-info":[{"award-number":["ZDYF2022SHFZ026"]}]},{"name":"Hainan Province Science and Technology Special Fund","award":["62163010"],"award-info":[{"award-number":["62163010"]}]},{"name":"Hainan Province Science and Technology Special Fund","award":["cstc2021jcyj-msxmX0891"],"award-info":[{"award-number":["cstc2021jcyj-msxmX0891"]}]},{"name":"Hainan Province Science and Technology Special Fund","award":["2019RC117"],"award-info":[{"award-number":["2019RC117"]}]},{"name":"National Natural Science Foundation of China","award":["ZDYF2022SHFZ026"],"award-info":[{"award-number":["ZDYF2022SHFZ026"]}]},{"name":"National Natural Science Foundation of China","award":["62163010"],"award-info":[{"award-number":["62163010"]}]},{"name":"National Natural Science Foundation of China","award":["cstc2021jcyj-msxmX0891"],"award-info":[{"award-number":["cstc2021jcyj-msxmX0891"]}]},{"name":"National Natural Science Foundation of China","award":["2019RC117"],"award-info":[{"award-number":["2019RC117"]}]},{"name":"General Program of the Natural Science Foundation of Chongqing Province of China","award":["ZDYF2022SHFZ026"],"award-info":[{"award-number":["ZDYF2022SHFZ026"]}]},{"name":"General Program of the Natural Science Foundation of Chongqing Province of China","award":["62163010"],"award-info":[{"award-number":["62163010"]}]},{"name":"General Program of the Natural Science Foundation of Chongqing Province of China","award":["cstc2021jcyj-msxmX0891"],"award-info":[{"award-number":["cstc2021jcyj-msxmX0891"]}]},{"name":"General Program of the Natural Science Foundation of Chongqing Province of China","award":["2019RC117"],"award-info":[{"award-number":["2019RC117"]}]},{"name":"High Level Talent Project of the Natural Science Foundation of Hainan Province of China","award":["ZDYF2022SHFZ026"],"award-info":[{"award-number":["ZDYF2022SHFZ026"]}]},{"name":"High Level Talent Project of the Natural Science Foundation of Hainan Province of China","award":["62163010"],"award-info":[{"award-number":["62163010"]}]},{"name":"High Level Talent Project of the Natural Science Foundation of Hainan Province of China","award":["cstc2021jcyj-msxmX0891"],"award-info":[{"award-number":["cstc2021jcyj-msxmX0891"]}]},{"name":"High Level Talent Project of the Natural Science Foundation of Hainan Province of China","award":["2019RC117"],"award-info":[{"award-number":["2019RC117"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Exchanging gradient is a widely used method in modern multinode machine learning system (e.g., distributed training, Federated Learning). Gradients and weights of model has been presumed to be safe to delivery. However, some studies have shown that gradient inversion technique can reconstruct the input images on the pixel level. In this study, we review the research work of data leakage by gradient inversion technique and categorize existing works into three groups: (i) Bias Attacks, (ii) Optimization-Based Attacks, and (iii) Linear Equation Solver Attacks. According to the characteristics of these algorithms, we propose one privacy attack system, i.e., Single-Sample Reconstruction Attack System (SSRAS). This system can carry out image reconstruction regardless of whether the label can be determined. It can extends gradient inversion attack from a fully connected layer with bias terms to attack a fully connected layer and convolutional neural network with or without bias terms. We also propose Improved R-GAP Alogrithm, which can utlize DLG algorithm to derive ground truth. Furthermore, we introduce Rank Analysis Index (RA-I) to measure the possible of whether the user\u2019s raw image data can be reconstructed. This rank analysis derive virtual constraints Vi from weights. Compared with the most representative attack algorithms, this reconstruction attack system can recover a user\u2019s private training image with high fidelity and attack success rate. Experimental results also show the superiority of the attack system over some other state-of-the-art attack algorithms.<\/jats:p>","DOI":"10.3390\/s22197157","type":"journal-article","created":{"date-parts":[[2022,9,22]],"date-time":"2022-09-22T23:07:55Z","timestamp":1663888075000},"page":"7157","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Recover User\u2019s Private Training Image Data by Gradient in Federated Learning"],"prefix":"10.3390","volume":"22","author":[{"given":"Haimei","family":"Gong","sequence":"first","affiliation":[{"name":"College of Information and Communication Engineering, Hainan University, Haikou 570228, China"},{"name":"Hainan Technology and Business College, Haikou 571100, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Liangjun","family":"Jiang","sequence":"additional","affiliation":[{"name":"College of Information and Communication Engineering, Hainan University, Haikou 570228, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoyang","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Information and Communication Engineering, Hainan University, Haikou 570228, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanqi","family":"Wang","sequence":"additional","affiliation":[{"name":"Funky-Tech (Shenzhen) Co., Ltd., Shenzhen 518000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lei","family":"Wang","sequence":"additional","affiliation":[{"name":"College of Information and Communication Engineering, Hainan University, Haikou 570228, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ke","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Automation, Chongqing University, Chongqing 400044, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,9,21]]},"reference":[{"key":"ref_1","unstructured":"Ju, C., Zhao, R., Sun, J., Wei, X., Zhao, B., Liu, Y., Li, H., Chen, T., Zhang, X., and Gao, D. (2020, January 18). Privacy-preserving technology to help millions of people: Federated prediction model for stroke prevention. Proceedings of the Workshop on Federated Learning for Data Privacy and Confidentiality in Conjunction with IJCAI, Yokohama, Japan."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Li, W., Milletar, F., and Xu, E.A. (2019, January 8\u201310). Privacy-preserving federated brain tumour segmentation. Proceedings of the International Workshop on Machine Learning in Medical Imaging, London, UK.","DOI":"10.1007\/978-3-030-32692-0_16"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1080\/09540091.2021.1936455","article-title":"Applications of federated learning in smart cities: Recent advances, taxonomy, and open challenges","volume":"34","author":"Zheng","year":"2022","journal-title":"Connect. Sci."},{"key":"ref_4","unstructured":"McMahan, H.B., Moore, E., Ramage, D., Hampson, S., and Arcas, B.A.y. (2017, January 20\u201322). Communication-Efficient Learning of Deep Networks from Decentralized Data. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS), Ft. Lauderdale, FL, USA."},{"key":"ref_5","unstructured":"Jakub, K., McMahan, B.H., Ramage, D., and Peter, R. (2016). Federated optimization: Distributed machine learning for on-device intelligence. arXiv."},{"key":"ref_6","unstructured":"McMahan, H.B., Moore, E., Ramage, D., and Arcas, B.A.y. (2016). Federated Learning of Deep Networks using Model Averaging. arXiv."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"12598","DOI":"10.1038\/s41598-020-69250-1","article-title":"Federated learning in medicine: Facilitating multi-institutional collaborations without sharing patient data","volume":"10","author":"Sheller","year":"2020","journal-title":"Sci. Rep."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1109\/MIS.2021.3082561","article-title":"SecureBoost: A Lossless Federated Learning Framework","volume":"36","author":"Cheng","year":"2021","journal-title":"IEEE Intell. Syst."},{"key":"ref_9","unstructured":"Liu, Z., Zhu, L., and Han, S. (2019, December 19). Deep Leakage from Gradients. Available online: http:\/\/github.com\/mit-han-lab\/dlg."},{"key":"ref_10","unstructured":"Zhao, B., Mopuri, K.R., and Bilen, H. (2020, January 08). idlg: Improved Deep Leakage from Gradients. Source Code. Available online: http:\/\/github.com\/PatrickZH\/Improved-Deep-Leakage-from-Gradients."},{"key":"ref_11","first-page":"16937","article-title":"Inverting Gradients\u2013How Easy Is It to Break Privacy in Federated Learning","volume":"33","author":"Geiping","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1333","DOI":"10.1109\/TIFS.2017.2787987","article-title":"Privacy-Preserving Deep Learning via Additively Homomorphic Encryption","volume":"13","author":"Phong","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_13","unstructured":"Wang, Z., Song, M., Zhang, Z., Song, Y., and Qi, H. (May, January 29). Beyond inferring class representatives: User-level privacy leakage from federated Learning. Proceedings of the IEEE Conference on Computer Communications, Paris, France."},{"key":"ref_14","unstructured":"Salem, A., Bhattacharya, A., Backes, M., Fritz, M., and Zhang, Y. (2019). Updates-leak: Data set inference and reconstruction attacks in online learning. arXiv."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Melis, L., Song, C., Cristofaro, E.D., and Shmatikov, V. (2019, January 19\u201323). Exploiting unintended feature leakage in collaborative learning. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00029"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1109\/MIS.2020.3014880","article-title":"Secure federated matrix Factorization","volume":"36","author":"Chai","year":"2020","journal-title":"IEEE Intell. Syst."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"503","DOI":"10.1007\/BF01589116","article-title":"On the limited memory bfgs method for large scale optimization","volume":"45","author":"Liu","year":"1989","journal-title":"Math. Program."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Wei, W., Liu, L., Loper, M., and Chow, K.-H. (2020). A framework for evaluating gradient leakage attacks in federated learning. arXiv.","DOI":"10.1007\/978-3-030-58951-6_27"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Fan, L., Ng, K.W., Ju, C., and Zhang, T. (2020). Rethinking Privacy Preserving Deep Learning: How to Evaluate and Thwart Privacy Attacks. Federated Learning, Springer. Lecture Notes in Computer Science, LNAI.","DOI":"10.1007\/978-3-030-63076-8_3"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2019, January 19\u201323). Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning. Proceedings of the IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00065"},{"key":"ref_21","unstructured":"Pan, X., Zhang, M., Yan, Y., Zhu, J., and Yang, M. (2020). Theory-oriented deep leakage from gradients via linear equation solver. arXiv."},{"key":"ref_22","unstructured":"Zhu, J., and Blaschko, M. (2021). R-GAP: Recursive Gradient Attack on Privacy. arXiv."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Yin, H., Mallya, A., Vahdat, A., Alvarez, J.M., Kautz, J., and Molchanov, P. (2021, January 19\u201325). See through Gradients: Image Batch Recovery via GradInversion. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Virtual.","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Scheliga, D., Mder, P., and Seeland, M. (2022, January 3\u20138). Precode\u2014A generic model extension to prevent deep gradient leakage. Proceedings of the WACV, Waikoloa, HI, USA.","DOI":"10.1109\/WACV51458.2022.00366"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Abadi, M., Chu, A., Goodfellow, I., McMahan, H.B., Mironov, I., Talwar, K., and Zhang, L. (2016, January 24\u201328). Deep learning with differential privacy. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978318"},{"key":"ref_26","first-page":"3079","article-title":"Secure Deep Neural Network Models Publishing Against Membership Inference Attacks via Training Task Parallelism","volume":"33","author":"Mao","year":"2022","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Truex, S., Baracaldo, N., Anwar, A., Steinke, T., Ludwig, H., and Zhang, R. (2020). A hybrid approach to privacy-preserving federated learning. arXiv.","DOI":"10.1145\/3338501.3357370"},{"key":"ref_28","unstructured":"Aryal, K., Gupta, M., and Abdelsalam, M. (2022, January 05). A Survey on Adversarial Attacks for Malware Analysis. Available online: https:\/\/www.researchgate.net\/publication\/356282100."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Kimmell, J.C., Abdelsalam, M., and Gupta, M. (2021). Analyzing Machine Learning Approaches for Online Malware Detection in Cloud. arXiv.","DOI":"10.1109\/SMARTCOMP52413.2021.00046"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"68066","DOI":"10.1109\/ACCESS.2021.3077498","article-title":"Recurrent Neural Networks Based Online Behavioural Malware Detection Techniques for Cloud Infrastructure","volume":"9","author":"Abdelsalam","year":"2021","journal-title":"IEEE Access"},{"key":"ref_31","first-page":"84","article-title":"Imagenet classification with deep convolutional neural networks","volume":"60","author":"Krizhevsky","year":"2012","journal-title":"NIPS"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Ganju, K., Wang, Q., Yang, W., Gunter, C.A., and Borisov, N. (2018, January 15\u201319). Property inference attacks on fully connected neural networks using permutation invariant representations. Proceedings of the ACM 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada.","DOI":"10.1145\/3243734.3243834"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., and Ristenpart, T. (2015, January 12\u201316). Model inversion attacks that exploit confidence information and basic countermeasures. Proceedings of the 22nd ACM SIGSAC Conference, Denver, CO, USA.","DOI":"10.1145\/2810103.2813677"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Pan, X., Zhang, M., Ji, S., and Yang, M. (2020, January 18\u201320). Privacy risks of general-purpose language models. Proceedings of the IEEE Symposium on Security and Privacy, San Francisco, CA, USA.","DOI":"10.1109\/SP40000.2020.00095"},{"key":"ref_35","unstructured":"Shokri, R., Strobel, M., and Zick, Y. (2019). Privacy risks of explaining machine learning models. arXiv."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H.B., Patel, S., Ramage, D., Segal, A., and Seth, K. (November, January 30). Practical secure aggregation for privacy-preserving machine learning. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3133982"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/19\/7157\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:36:28Z","timestamp":1760142988000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/19\/7157"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,21]]},"references-count":36,"journal-issue":{"issue":"19","published-online":{"date-parts":[[2022,10]]}},"alternative-id":["s22197157"],"URL":"https:\/\/doi.org\/10.3390\/s22197157","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9,21]]}}}