Breaking the Chain of Gradient Leakage in Vision Transformers

Python 3.6 Packagist Last Commit Maintenance Contributing

[arXiv] | [Codes] Yahui Liu1, Bin Ren1, Yue Song1, Wei Bi2, Nicu Sebe1 and Wei Wang1 1University of Trento, Italy, 2Tencent AI Lab, China

Visual comparisons on image recovery with gradient attacks.


Dataset Download Link
ImageNet train,val
  • Download the datasets by using codes in the scripts folder.

  |    |__category1
  |    |    |__xxx.jpg
  |    |    |__...
  |    |__category2
  |    |    |__xxx.jpg
  |    |    |__...
  |    |__...
       |    |__xxx.jpg
       |    |__...
       |    |__xxx.jpg
       |    |__...


After prepare the datasets, we can simply start the training with 8 NVIDIA V100 GPUs:

$ sh


  • Accuracy on Masked Jigsaw Puzzle
$ python3 
  • Consistency on Masked Jigsaw Puzzle
$ python3
  • Evaluations on image reconstructions

See the codes MSE, PSNR/SSIM, FFT2D, LPIPS.

Gradient Attack

We refer to the public repo: JonasGeiping/breaching.


This repo is built on several existing projects:


If you take use of our code, please cite our papers:

    author    = {Liu, Yahui and Ren, Bin and Song, Yue and Bi, Wei and Sebe, Nicu and Wang, Wei},
    title     = {Breaking the Chain of Gradient Leakage in Vision Transformers},
    journal    = {arXiv:2205.12551},
    year      = {2022}

If you have any questions, please contact me without hesitation (yahui.liu AT


View Github