This invention relates to the field of
federated learning privacy and security technology, and proposes an enhanced
federated learning gradient leakage
attack method based on
singular value decomposition, comprising three steps: gradient denoising projection,
noise variable optimization, and structure regularization. Gradient denoising projection performs
singular value decomposition on the intercepted perturbed gradient, extracts the
principal direction to construct a projection matrix, and restricts the gradient matching process to the
signal-dominated subspace.
Noise variable optimization introduces auxiliary
noise variables, jointly calculates the virtual gradient with virtual data, projects it onto the principal subspace, calculates the
gradient projection loss, and sets independent learning rates for joint optimization of the virtual data and
noise variables. Structure regularization calculates the total
variational regularization loss of the reconstructed image, weights it with the
gradient projection loss to form a total
loss function, iteratively updates the virtual data, and then reconstructs and recovers the original training data. Even if the
client gradient is perturbed, this invention can still reconstruct and recover the
client's original training data with high quality from the perturbed gradient.