跳到主要导航 跳到搜索 跳到主要内容

GradInvDiff: Stealing Medical Privacy in Federated Learning via Diffusion-Based Gradient Inversion

  • Zhiyuan Wang
  • , Daisong Gan
  • , Wenzhuo Fang
  • , Yuliang Zhu
  • , Kun Liu*
  • *此作品的通讯作者
  • Beijing Institute of Technology
  • Shenzhen Institute of Advanced Technology
  • The University of Nottingham Ningbo China

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Federated learning (FL) has become a crucial technique for medical imaging analysis, enabling multiple institutions to train machine learning models while preserving patient privacy collaboratively. However, recent research has uncovered the vulnerability of shared gradients in FL, which can be exploited through the gradient inversion attack (GIA) to reconstruct private medical images. While existing methods show promise in generic image tasks, their application to high-resolution medical images remains underexplored and ineffective due to data complexity. This paper introduces GradInvDiff, a novel GIA tailored for medical FL scenarios. Unlike traditional methods that rely solely on gradient guidance, our approach combines diffusion models with gradient matching optimization to iteratively refine the inference process. By replacing the standard random noise in the diffusion process with a direction derived from the difference between the optimized and original means, we inject a gradient-based condition into the noise to enhance image reconstruction quality. This method enables high-quality, pixel-level reconstruction of private medical images, even in the presence of large batch sizes or gradient noise. Our experiments demonstrate that GradInvDiff outperforms existing state-of-the-art gradient inversion methods and shows better accuracy and visibility when attacking medical FL models. We hope that this paper can raise public awareness of privacy leakage risks when using medical FL.

源语言英语
主期刊名Medical Image Computing and Computer Assisted Intervention, MICCAI 2025 - 28th International Conference, 2025, Proceedings
编辑James C. Gee, Jaesung Hong, Carole H. Sudre, Polina Golland, Jinah Park, Daniel C. Alexander, Juan Eugenio Iglesias, Archana Venkataraman, Jong Hyo Kim
出版商Springer Science and Business Media Deutschland GmbH
262-272
页数11
ISBN(印刷版)9783032051844
DOI
出版状态已出版 - 2026
已对外发布
活动28th International Conference on Medical Image Computing and Computer Assisted Intervention, MICCAI 2025 - Daejeon, 韩国
期限: 23 9月 202527 9月 2025

出版系列

姓名Lecture Notes in Computer Science
15973 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议28th International Conference on Medical Image Computing and Computer Assisted Intervention, MICCAI 2025
国家/地区韩国
Daejeon
时期23/09/2527/09/25

指纹

探究 'GradInvDiff: Stealing Medical Privacy in Federated Learning via Diffusion-Based Gradient Inversion' 的科研主题。它们共同构成独一无二的指纹。

引用此