[论文] Temporal Gradient Inversion for Private Trajectory Reconstruction in E...
研究领域: ML 作者: Sudip Bhujel, Shanghao Shi, Ruiquan Huang, Ning Zhang, Yang Xiao 发布时间: 2026-09-24 arXiv: 2609.30258
论文概要
研究领域: ML 作者: Sudip Bhujel, Shanghao Shi, Ruiquan Huang, Ning Zhang, Yang Xiao 发布时间: 2026-09-24 arXiv: 2609.30258
中文摘要
具身强化学习智能体的分布式学习通过将原始传感器数据保留在设备端、仅向服务器传输策略梯度,从而提供了一定程度的隐私保护。然而,时间结构可能会将信息泄露放大到超出单帧攻击的水平。我们提出 TRACE(针对连续编码的时间重建攻击),一种摊销化的时间梯度反演攻击,能够以自回归方式从逐步的策略学习梯度中重建私有的观察-动作轨迹序列。该攻击利用了以往单帧方法所忽略的两个结构性信号:(i)连续具身梯度之间的跨时间相关性——我们通过条件互信息上界对其进行形式化;(ii)从策略头梯度结构中恢复动作的闭式解——我们证明当标准熵正则化足够小时该恢复是精确的。在留出的具身场景上,TRACE 达到了 18.8 dB 的 PSNR,动作恢复近乎完美,每帧重建耗时仅 3-4.5 毫秒,在所有重建指标上均优于基于学习的基线,同时比优化类攻击快数个数量级。进一步的评估展示了 TRACE 在循环、残差和紧凑 Transformer 受害者架构、多模态输入以及更大离散动作空间上的广泛适用性。防御实验表明,保护时间梯度流可能需要引入序列感知的隐私机制。
原文摘要
Distributed learning in embodied reinforcement-learning agents offers a degree of privacy by retaining raw sensor data on-device and transmitting only policy gradients to the server. Yet temporal structure can amplify this leakage beyond single-frame attacks. We introduce Temporal Reconstruction Attack on Consecutive Encodings (TRACE), an amortized temporal gradient-inversion attack that autoregressively reconstructs the sequence of private observation-action trajectories from per-step policy-learning gradients. The attack exploits two structural signals ignored by prior single-frame methods: (i) cross-time correlation between successive embodied gradients, which we formalize via a conditional mutual-information bound, and (ii) closed-form action recovery from policy-head gradient structur...
*自动采集于 2026-09-28*
#论文 #arXiv #ML #小凯