Images in motion?: a first look into video leakage in federated learning
dc.contributor.author | Rasul, Md Fazle, author | |
dc.contributor.author | Ray, Indrakshi, advisor | |
dc.contributor.author | Jayasumana, Anura P., committee member | |
dc.contributor.author | Bezawada, Bruhadeshwar, committee member | |
dc.contributor.author | Simske, Steve, committee member | |
dc.date.accessioned | 2025-09-01T10:42:14Z | |
dc.date.available | 2026-08-25 | |
dc.date.issued | 2025 | |
dc.description.abstract | Federated learning (FL) allows multiple entities to train a shared model collaboratively. Its core, privacy-preserving principle is that participants only exchange model updates, such as gradients, and never their raw, sensitive data. This approach is fundamental for applications in domains where privacy and confidentiality are important. However, the security of this very mechanism is threatened by gradient inversion attacks, which can reverse-engineer private training data directly from the shared gradients, defeating the purpose of FL. While the impact of these attacks is known for image, text, and tabular data, their effect on video data remains an unexamined area of research. This paper presents the first analysis of video data leakage in FL via gradient inversion attacks. We evaluate two common video classification approaches: one employing pre-trained feature extractors and another that processes raw video frames with simple transformations. Our results indicate that the use of feature extractors offers greater resilience against gradient inversion attacks. We also demonstrate that image super-resolution techniques can enhance the frames, extracted through gradient inversion attacks, enabling attackers to reconstruct higher-quality videos. Our experiments validate this across scenarios where the attacker has access to zero, one, or more reference frames from the target environment. We find that although feature extractors make attacks more challenging, leakage is still possible if the classifier lacks sufficient complexity. We, therefore, conclude that video data leakage in FL is a viable threat and the conditions under which it occurs warrant further investigation. | |
dc.format.medium | born digital | |
dc.format.medium | masters theses | |
dc.identifier | Rasul_colostate_0053N_19169.pdf | |
dc.identifier.uri | https://hdl.handle.net/10217/241805 | |
dc.identifier.uri | https://doi.org/10.25675/3.02125 | |
dc.language | English | |
dc.language.iso | eng | |
dc.publisher | Colorado State University. Libraries | |
dc.relation.ispartof | 2020- | |
dc.rights | Copyright and other restrictions may apply. User is responsible for compliance with all applicable laws. For information about copyright law, please see https://libguides.colostate.edu/copyright. | |
dc.rights.access | Embargo expires: 08/25/2026. | |
dc.subject | federated learning | |
dc.subject | machine learning | |
dc.subject | deep leakage | |
dc.subject | video data | |
dc.subject | gradient inversion attack | |
dc.title | Images in motion?: a first look into video leakage in federated learning | |
dc.type | Text | |
dcterms.embargo.expires | 2026-08-25 | |
dcterms.embargo.terms | 2026-08-25 | |
dcterms.rights.dpla | This Item is protected by copyright and/or related rights (https://rightsstatements.org/vocab/InC/1.0/). You are free to use this Item in any way that is permitted by the copyright and related rights legislation that applies to your use. For other uses you need to obtain permission from the rights-holder(s). | |
thesis.degree.discipline | Computer Science | |
thesis.degree.grantor | Colorado State University | |
thesis.degree.level | Masters | |
thesis.degree.name | Master of Science (M.S.) |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Rasul_colostate_0053N_19169.pdf
- Size:
- 682.68 KB
- Format:
- Adobe Portable Document Format