More Noise, Less Damage: Enhanced Noise Injection Against Gradient-Inversion in Federated Learning
Abstract
Gradient inversion attacks expose a key vulnerability of federated learning: even when raw data remain on local devices, shared gradients can still leak sensitive information about training samples. Existing defenses typically mitigate this risk by perturbing gradients before transmission, but these perturbations often interfere with optimization and reduce model performance. In this paper, we show that stronger noise injection need not lead to a proportional loss in utility when the noise is introduced in a structured way. Building on this insight, we propose TIDE, a structured noise injection framework designed to improve the privacy–utility trade-off. TIDE injects larger noise at each training step while exploiting a telescoping effect that causes perturbations to partially cancel over the course of training. As a result, it provides stronger protection for shared gradients with smaller perturbations to the optimization dynamics. We theoretically show that, on smooth nonconvex objectives at fixed learning rate (), TIDE's residual stationarity floor scales as whereas standard DPSGD incurs an floor; equivalently, with optimally tuned step sizes TIDE attains a strictly faster convergence rate compared to DPSGD's . This separation enables TIDE to maintain better optimization stability despite using larger noise at each step. Empirically, TIDE remains effective with noise levels up to larger than those used in standard approaches, while consistently achieving better model performance. Extensive experiments across multiple datasets and against a range of inversion attacks confirm that TIDE significantly enhances gradient privacy while preserving competitive test accuracy.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.