AAAI 2026technical0 citations

Venom: Liquid Diffusion-Guided Gradient Inversion for Breaking Differential Privacy in Federated Learning

Bin Hu, Jingling Yuan, Jiawei Jiang, Chuang Hu

Abstract

Gradient perturbation mechanisms, such as differential privacy (DP), aim to defend against gradient inversion attacks (GIA) by injecting noise into the shared gradients. Recent studies have shown that DP-based defenses lack robustness against advanced GIAs. However, existing gradient inversion methods typically rely on iterative refinement and assume static noise, resulting in low efficiency and limited reconstruction fidelity under high-noise conditions. In this paper, we propose Venom, a novel gradient inversion attack method based on a liquid diffusion mechanism. Venom reconstructs private data directly from DP-protected gradients without requiring any prior knowledge of the noise distribution. Specifically, we design a Structural Prior Extraction (SPE) module that analytically extracts deep feature representations from perturbed gradients through energy-based aggregation, enabling stable pre-reconstruction of users

BibTeX
@inproceedings{aaai2026_venomliquiddiffu,
  title = {Venom: Liquid Diffusion-Guided Gradient Inversion for Breaking Differential Privacy in Federated Learning},
  author = {Bin Hu and Jingling Yuan and Jiawei Jiang and Chuang Hu},
  booktitle = {AAAI 2026},
  year = {2026}
}