TY - JOUR
T1 - Self-Correcting Client-Initiated Gradient Inversion via Adaptive Diffusion Control
AU - Zhao, Yi
AU - Hu, Jincheng
AU - Zhang, Nan
AU - Liu, Zhen
AU - Zhu, Liehuang
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Federated learning (FL) ostensibly safeguards data privacy by sharing only model updates. However, gradient inversion attacks (GIAs) have exposed critical vulnerabilities in this paradigm. While prior literature predominantly assumes a privileged server-side adversary, this work addresses the more insidious and practical threat of client-initiated attacks. Existing client-initiated methodologies remain fragile, treating inversion as a static, single-shot optimization problem that frequently succumbs to catastrophic optimization collapse due to the stochastic nature of FL dynamics. To overcome these limitations, we propose DCPT (i.e., Diffusion-driven Client-initiated Privacy Theft), a resilient framework that shifts the paradigm toward multi-stage adaptive inversion. Specifically, DCPT integrates a novel adaptive control framework with a closed-loop feedback mechanism, monitoring reconstruction fidelity to dynamically alternate between Exploitation and Exploration, thereby achieving self-correcting. To further guarantee robustness against gradient drift, we incorporate a rolling history constraint for temporal regularization and a bilevel optimization for on-the-fly prior adaptation. Extensive experiments on MNIST and CIFAR-10 demonstrate that DCPT achieves state-of-the-art reconstruction fidelity. Crucially, it also achieves unprecedented multi-round stability and resilience, highlighting the urgent need for advanced defenses against generative client-initiated adversaries.
AB - Federated learning (FL) ostensibly safeguards data privacy by sharing only model updates. However, gradient inversion attacks (GIAs) have exposed critical vulnerabilities in this paradigm. While prior literature predominantly assumes a privileged server-side adversary, this work addresses the more insidious and practical threat of client-initiated attacks. Existing client-initiated methodologies remain fragile, treating inversion as a static, single-shot optimization problem that frequently succumbs to catastrophic optimization collapse due to the stochastic nature of FL dynamics. To overcome these limitations, we propose DCPT (i.e., Diffusion-driven Client-initiated Privacy Theft), a resilient framework that shifts the paradigm toward multi-stage adaptive inversion. Specifically, DCPT integrates a novel adaptive control framework with a closed-loop feedback mechanism, monitoring reconstruction fidelity to dynamically alternate between Exploitation and Exploration, thereby achieving self-correcting. To further guarantee robustness against gradient drift, we incorporate a rolling history constraint for temporal regularization and a bilevel optimization for on-the-fly prior adaptation. Extensive experiments on MNIST and CIFAR-10 demonstrate that DCPT achieves state-of-the-art reconstruction fidelity. Crucially, it also achieves unprecedented multi-round stability and resilience, highlighting the urgent need for advanced defenses against generative client-initiated adversaries.
KW - Diffusion Model
KW - Federated Learning (FL)
KW - Gradient Inversion Attacks (GIAs)
KW - Privacy Theft
UR - https://www.scopus.com/pages/publications/105046295819
U2 - 10.1109/TDSC.2026.3717616
DO - 10.1109/TDSC.2026.3717616
M3 - Article
AN - SCOPUS:105046295819
SN - 1545-5971
JO - IEEE Transactions on Dependable and Secure Computing
JF - IEEE Transactions on Dependable and Secure Computing
ER -