acceptodds
Under review as a conference paper at ICLR 2027

ADAN: Adaptive Direction-Aware Noise for Defending Iterative Gradient Inversion Attacks

Abstract

Iterative training data reconstruction is a class of gradient inversion attacks (GIAs) in which an adversary repeatedly updates a dummy input to align its gradient with the gradients of a target model, progressively recovering the ground-truth training data. Existing GIAs operate under a curious-but-honest setting. This setting provides the attackers with a significant advantage because they can utilize the model parameters to calculate the exact gradients during iterative optimization. By contrast, in this work, we consider a more challenging black-box setting in which the attacker has no access to model parameters. Based on this setting, we propose **Adaptive Direction-Aware Noise (ADAN)**, a mechanism that injects input-dependent, non-isotropic Gaussian noise into each queried gradient. ADAN employs a neural network to learn per-coordinate noise magnitudes adapted to the input data distribution, effectively steering the optimization geometry of iterative GIAs. Empirical results show that ADAN substantially outperforms isotropic gradient perturbation methods across multiple datasets and attack variants.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.