Skip to main content
Back to timeline
arXivSource publication:

PI-SME reconstructs FedAvg multi-step gradient updates via Gauss–Legendre quadrature along a learnable Bézier path, surpassing the strongest surrogate baseline on CIFAR-100 and FEMNIST

Related research and updates

Synopsis

The work proposes the Path-Integral Surrogate Model Extension (PI-SME), which treats the accumulated multi-step update in FedAvg as a path integral of the gradient field along the client trajectory and approximates it by Gauss–Legendre quadrature over several nodes along a learnable Bézier path; on CIFAR-100 and FEMNIST images, PI-SME reconstructs private inputs more faithfully than the strongest surrogate baseline NL-SME on several inversion metrics and the matching loss, with the largest gains on long trajectories and class-restricted batches.

Source-provided article image: A Path Integral Surrogate for Multi-Step Gradient Inversion in Federated Learning
Figure 1 ·

Figure 1: Sample inversions using PI-SME on CIFAR-100; each column shows the original (top) and its reconstruction (bottom).

arXiv

Interpretation

It reframes multi-step gradient inversion as a quadrature problem: the FedAvg update is a discrete line integral of the gradient field along the client's local trajectory, so the object worth matching is the path integral rather than the gradient at any single weight. Prior SME and NL-SME fit a surrogate path between the endpoints but still read the surrogate gradient at a single state; PI-SME is, to the authors' knowledge, the first gradient inversion attack to model the multi-step update as a path integral and use multi-node quadrature for inversion. The paper derives the accumulated update in Eq. (1) and the mean gradient direction in Eq. (2), notes that the scalar mean value theorem does not carry over to the vector-valued high-dimensional gradients attacked here, and the path-consistency test confirms on real trajectories that the best single point is measurably worse than quadrature over several nodes.

It approximates the path integral with an n-node Gauss–Legendre rule along a learnable Bézier curve, where the mapped weights form a weighted average of the surrogate gradient at fixed points of the curve. Relative to NL-SME's single-point read, PI-SME resolves the path at n nodes, each costing one backward pass, the dominant cost of the attack, while reusing NL-SME's per-coordinate calibration vector and the anisotropic total-variation prior. The paper gives the quadrature formulas and weight normalization in Eqs. (5)–(8), states the rule is exact for polynomial integrands of degree up to 2n−1, and specifies the optimization setup (Adam, learning rates, regularizer weights).

On CIFAR-100 and FEMNIST, PI-SME improves on NL-SME in every setting and on every metric, while single-step and prior-enhanced methods trail the surrogate line by a wide margin. The gain tracks setting difficulty: on CIFAR-100 the PSNR gain over NL-SME is larger at the longer trajectory, on FEMNIST it is about the same at both trajectory lengths, and SSIM, FSIM, LPIPS, and the matching loss move the same way. Table 1 compares PI-SME with SME, NL-SME, IG, GI-NAS, and DGGI on both datasets at two trajectory lengths; victim networks are small CNNs with two convolutional layers followed by two fully connected layers, and the node count is fixed from the ablation.

The path-consistency test shows that a multi-node quadrature, fitted only from the two observed endpoints, achieves a lower honest cosine loss than the best single-point reference obtained by scanning the entire true trajectory. Even a two-node quadrature cuts the reference by roughly a factor of three, and additional nodes lower it further before saturating; the best single state moves along the path as trajectory length grows, so no fixed position is adequate across settings. The adversary is granted oracle access to the full sequence of true intermediate states and the private batch, no dummy data is optimized, and the comparison is purely between gradient directions and the true mean direction, reported at two trajectory lengths.

Perspective

The result applies to an honest-but-curious server under FedAvg multi-step local training on image classification, with victim models that are small CNNs of two convolutional layers followed by two fully connected layers, on CIFAR-100 and FEMNIST. It lets researchers evaluate inversion strength in the regimes where single-point approximation is weakest, namely long trajectories and class-restricted batches, and gives defenders a baseline closer to realistic accumulated updates; the node count is fixed from an ablation, and each node adds one backward pass.

The specific values in the original tables are not fully rendered in the text, so exact metrics for each method across the two datasets and two trajectory lengths can only be inferred from the prose. The node count is chosen by empirical ablation rather than from a principled bound, and larger node counts give no monotone gain; all surrogate methods degrade sharply on class-deficient batches, and the reason remains to be explained. These are directions for follow-up work rather than objections to the present results.

Sources