f3d04980ae0ae12c.tex
1: \begin{abstract}
2: Federated learning (FL) empowers privacy-preservation in model training by only exposing users' model gradients. Yet, FL users are susceptible to gradient inversion (GI) attacks which can reconstruct original training data such as images based on exposed model gradients.  %    Privacy concerns in federated learning are underscored by the effectiveness of gradient inversion attacks, revealing vulnerabilities in data security. 
3: However, reconstructing  high-quality images by existing GI attacks is extremely time consuming due to invisible labels and the slow convergence of image reconstruction algorithms. To overcome these drawbacks, in this work we present a novel fast-convergent GI attack algorithm, called $\textbf{EGI}$ (express gradient inversion). There are two components in  $\textbf{EGI}$: 1) $\textbf{A}$dditional $\textbf{C}$onvolution $\textbf{B}$lock ($\textbf{ACB}$) which can infer labels and achieve up to  a remarkable 13\% improvement compared with existing works; 2) $\textbf{T}$otal variance, three-channel m$\textbf{E}$an and c$\textbf{A}$nny edge detection regularization term ($\textbf{TEA}$), which is a white-box attack strategy to reconstruct images based on labels inferred by $\textbf{ACB}$.  $\textbf{EGI}$ can considerably diminish 87\% time costs while achieving superb inversion quality in ImageNet images. Notably, with a batch size of 1, $\textbf{TEA}$ exhibits a 9.4 higher Peak Signal-to-Noise Ratio (PSNR) compared to the state-of-the-art baselines.
4: \end{abstract}
5: