Federated Learning (FL) enables collaborative training of Machine Learning (ML) models across multiple clients while preserving their privacy. Rather than sharing raw data, federated clients transmit locally computed updates to train the global model. Although this paradigm offers stronger privacy guarantees than centralized ML, adversaries can still exploit client updates to infer sensitive properties of the underlying training data or even reconstruct it. Under the honest-but-curious threat model, Gradient Inversion Attacks (GIAs) attempt to reconstruct training data by reversing intermediate updates using optimization-based techniques. We observe that these approaches usually reconstruct noisy approximations of the original inputs, whose quality can be enhanced with specialized denoising models. This paper presents Gradient Update Inversion with DEnoising (GUIDE), a novel methodology that leverages diffusion models as denoising tools to improve image reconstruction attacks in FL. GUIDE can be integrated into any GIAs that exploit surrogate datasets, a widely adopted assumption in GIAs literature. We comprehensively evaluate our approach in three attack scenarios that use different FL algorithms, models, and datasets. Our results demonstrate that GUIDE integrates seamlessly with two state-of-the-art GIAs, substantially improving reconstruction quality across multiple metrics. Specifically, GUIDE achieves up to 55% higher perceptual similarity, as measured by the DreamSim metric.

GUIDE: Enhancing Gradient Inversion Attacks in Federated Learning with Denoising Models

Vincenzo Carletti;Pasquale Foggia;Carlo Mazzocca;Giuseppe Parrella
;
Mario Vento
2026

Abstract

Federated Learning (FL) enables collaborative training of Machine Learning (ML) models across multiple clients while preserving their privacy. Rather than sharing raw data, federated clients transmit locally computed updates to train the global model. Although this paradigm offers stronger privacy guarantees than centralized ML, adversaries can still exploit client updates to infer sensitive properties of the underlying training data or even reconstruct it. Under the honest-but-curious threat model, Gradient Inversion Attacks (GIAs) attempt to reconstruct training data by reversing intermediate updates using optimization-based techniques. We observe that these approaches usually reconstruct noisy approximations of the original inputs, whose quality can be enhanced with specialized denoising models. This paper presents Gradient Update Inversion with DEnoising (GUIDE), a novel methodology that leverages diffusion models as denoising tools to improve image reconstruction attacks in FL. GUIDE can be integrated into any GIAs that exploit surrogate datasets, a widely adopted assumption in GIAs literature. We comprehensively evaluate our approach in three attack scenarios that use different FL algorithms, models, and datasets. Our results demonstrate that GUIDE integrates seamlessly with two state-of-the-art GIAs, substantially improving reconstruction quality across multiple metrics. Specifically, GUIDE achieves up to 55% higher perceptual similarity, as measured by the DreamSim metric.
2026
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11386/4960615
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact