Skip to main content

Investigating the Vulnerability of Federated Learning-Based Diabetic Retinopathy Grade Classification to Gradient Inversion Attacks

  • Conference paper
  • First Online:
Ophthalmic Medical Image Analysis (OMIA 2022)

Part of the book series: Lecture Notes in Computer Science ((LNCS,volume 13576))

Included in the following conference series:

Abstract

Diabetic retinopathy (DR) is a serious vision-threatening condition associated with diabetes and is the leading cause of visual impairment for working-age adults worldwide. Smartphone-based fundus imaging (SBFI) has the potential to be combined with machine learning-based DR screening procedures to simultaneously improve global health equity and the prognosis of DR by increasing patient accessibility to low-cost DR screening services. Federated learning is a promising method to train machine learning models for DR grade classification using large amounts of SBFI data, which can protect the privacy of sensitive patient data at the same time. However, gradient inversion attacks have been shown to be able to reconstruct private data using the model parameter gradient information transmitted during federated learning updates. The purpose of this paper is to investigate the privacy threat that gradient inversion attacks pose for reconstructing identifiable retinal fundus images during federated learning-based DR grade classification training. Specifically, a novel metric called “Segmentation Matching Score” (SMS) is proposed to quantify clinically relevant features present in fundus images reconstructed during a gradient inversion attack that could be exploited for patient identification information. Experimental results based on the FGADR dataset demonstrate that reconstructed images could be correctly matched to their corresponding source images using the SMS metric with a top-1 accuracy of 72.0%. These findings indicate that gradient inversion attacks pose a significant threat for federated learning-based DR grade classification models and warrant further investigation into viable defense strategies.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

References

  1. Dai, L., et al.: A deep learning system for detecting diabetic retinopathy across the disease spectrum. Nat. Commun. 12, 3242 (2021)

    Article  Google Scholar 

  2. Staurenghi, G., et al.: Impact of baseline diabetic retinopathy severity scale scores on visual outcomes in the VIVID-DME and VISTA-DME studies. Br. J. Ophthalmol. 102, 954–958 (2018)

    Article  Google Scholar 

  3. Gulshan, V., et al.: Development and validation of a deep learning algorithm for detection of diabetic retinopathy in retinal fundus photographs. JAMA 316, 2402 (2016)

    Article  Google Scholar 

  4. Ruamviboonsuk, P., et al.: Deep learning versus human graders for classifying diabetic retinopathy severity in a nationwide screening program. npj Digit. Med. 2, 1–9 (2019)

    Google Scholar 

  5. Abràmoff, M.D., Lavin, P.T., Birch, M., Shah, N., Folk, J.C.: Pivotal trial of an autonomous AI-based diagnostic system for detection of diabetic retinopathy in primary care offices. npj Digit. Med. 1, 1–8 (2018)

    Google Scholar 

  6. MacEachern, S.J., Forkert, N.D.: Machine learning for precision medicine. Genome 64, 416–425 (2021)

    Article  Google Scholar 

  7. Byrne, M.M., et al.: Cost of a community-based diabetic retinopathy screening program. Diabetes Care 37, e236–e237 (2014)

    Article  Google Scholar 

  8. Iqbal, U.: Smartphone fundus photography: a narrative review. Int. J. Retina Vitreous 7, 44 (2021)

    Article  Google Scholar 

  9. Nazari Khanamiri, H., Nakatsuka, A., El-Annan, J.: Smartphone fundus photography. J. Vis. Exp., 55958 (2017). https://doi.org/10.3791/55958

  10. Wintergerst, M.W.M., Jansen, L.G., Holz, F.G., Finger, R.P.: Smartphone-based fundus imaging-where are we now? Asia Pac. J. Ophthalmol. 9, 308–314 (2020)

    Article  Google Scholar 

  11. Parasuraman, S., Sam, A.T., Yee, S.W.K., Chuon, B.L.C., Ren, L.Y.: Smartphone usage and increased risk of mobile phone addiction: a concurrent study. Int. J. Pharm. Investig. 7, 125–131 (2017)

    Article  Google Scholar 

  12. Willemink, M.J., et al.: Preparing medical imaging data for machine learning. Radiology 295, 4–15 (2020)

    Article  Google Scholar 

  13. Farzin, H., Abrishami-Moghaddam, H., Moin, M.-S.: A novel retinal identification system. EURASIP J. Adv. Sig. Process. 2008(1), 1 (2008). https://doi.org/10.1155/2008/280635

    Article  MATH  Google Scholar 

  14. Akram, M.U., Abdul Salam, A., Khawaja, S.G., Naqvi, S.G.H., Khan, S.A.: RIDB: a dataset of fundus images for retina based person identification. Data Brief 33, 106433 (2020)

    Article  Google Scholar 

  15. Tuladhar, A., Gill, S., Ismail, Z., Forkert, N.D.: Building machine learning models without sharing patient data: a simulation-based analysis of distributed learning by ensembling. J. Biomed. Inform. 106, 103424 (2020)

    Article  Google Scholar 

  16. Konečný, J., McMahan, H.B., Ramage, D., Richtárik, P.: Federated optimization: distributed machine learning for on-device intelligence (2016). https://doi.org/10.48550/arXiv.1610.02527

  17. McMahan, B., Moore, E., Ramage, D., Hampson, S., Arcas, B.A.Y.: Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, pp. 1273–1282. PMLR (2017)

    Google Scholar 

  18. Zerka, F., et al.: Privacy preserving distributed learning classifiers – sequential learning with small sets of data. Comput. Biol. Med. 136, 104716 (2021)

    Article  Google Scholar 

  19. Yin, H., et al.: See through Gradients: image batch recovery via GradInversion. In: 2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 16332–16341. IEEE (2021). https://doi.org/10.1109/CVPR46437.2021.01607

  20. Zhu, L., Liu, Z., Han, S.: Deep leakage from gradients. In: Advances in Neural Information Processing Systems, vol. 32, Curran Associates, Inc. (2019)

    Google Scholar 

  21. Huang, Y., Gupta, S., Song, Z., Li, K., Arora, S.: Evaluating gradient inversion attacks and defenses in federated learning. In: Advances in Neural Information Processing Systems, vol. 34, pp. 7232–7241. Curran Associates, Inc. (2021)

    Google Scholar 

  22. Subbanna, N., Wilms, M., Tuladhar, A., Forkert, N.D.: An analysis of the vulnerability of two common deep learning-based medical image segmentation techniques to model inversion attacks. Sensors 21, 3874 (2021)

    Article  Google Scholar 

  23. Zhou, Y., Wang, B., Huang, L., Cui, S., Shao, L.: A benchmark for studying diabetic retinopathy: segmentation, grading, and transferability. IEEE Trans. Med. Imaging 40, 818–828 (2021)

    Article  Google Scholar 

  24. Qu, L., Balachandar, N., Zhang, M., Rubin, D.: Handling data heterogeneity with generative replay in collaborative learning for medical imaging. Med. Image Anal. 78, 102424 (2022)

    Article  Google Scholar 

  25. Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition (2015). https://doi.org/10.48550/arXiv.1409.1556

  26. Wang, P., Hu, Q., Fang, Z., Zhao, C., Cheng, J.: DeepSearch: a fast image search framework for mobile devices. ACM Trans. Multimedia Comput. Commun. Appl. 14, 1–22 (2018)

    Google Scholar 

  27. Geiping, J., Bauermeister, H., Dröge, H., Moeller, M.: Inverting gradients - how easy is it to break privacy in federated learning? In: Advances in Neural Information Processing Systems, vol. 33, pp. 16937–16947. Curran Associates, Inc. (2020)

    Google Scholar 

  28. Lin, T.-Y., et al.: Feature pyramid networks for object detection. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 936–944. IEEE (2017). https://doi.org/10.1109/CVPR.2017.106

  29. Wang, Z., Bovik, A.C., Sheikh, H.R., Simoncelli, E.P.: Image quality assessment: from error visibility to structural similarity. IEEE Trans. Image Process. 13, 600–612 (2004)

    Article  Google Scholar 

  30. Zhang, R., Isola, P., Efros, A.A., Shechtman, E., Wang, O.: The unreasonable effectiveness of deep features as a perceptual metric. In: 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition, pp. 586–595. IEEE (2018). https://doi.org/10.1109/CVPR.2018.00068

  31. Nilsson, J., Akenine-Möller, T.: Understanding SSIM. arXiv preprint arXiv:2006.13846 (2020)

  32. Hofbauer, H., Rathgeb, C., Uhl, A., Wild, P.: Image metric-based biometric comparators: a supplement to feature vector-based Hamming distance? In: 2012 BIOSIG - Proceedings of the International Conference of Biometrics Special Interest Group (BIOSIG), pp. 1–5 (2012)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Christopher Nielsen .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2022 The Author(s), under exclusive license to Springer Nature Switzerland AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Nielsen, C., Tuladhar, A., Forkert, N.D. (2022). Investigating the Vulnerability of Federated Learning-Based Diabetic Retinopathy Grade Classification to Gradient Inversion Attacks. In: Antony, B., Fu, H., Lee, C.S., MacGillivray, T., Xu, Y., Zheng, Y. (eds) Ophthalmic Medical Image Analysis. OMIA 2022. Lecture Notes in Computer Science, vol 13576. Springer, Cham. https://doi.org/10.1007/978-3-031-16525-2_19

Download citation

  • DOI: https://doi.org/10.1007/978-3-031-16525-2_19

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-031-16524-5

  • Online ISBN: 978-3-031-16525-2

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics