VAHANA: Hardware-Aware Noise Addition Against Gradient Inversion Attacks
Abstract
Federated learning (FL) enables clients to collaboratively train a global model by sharing gradient updates instead of raw data. However, recent studies show that these shared gradients can be exploited to reconstruct private training data through gradient inversion attacks, posing a serious threat to client privacy. A common defense strategy is gradient obfuscation, which perturbs gradients before transmission; however, it relies on costly hardware components, such as Gaussian samplers and floating-point (FP) multipliers, making it unsuitable for resource-constrained edge devices. Approximate circuits-extensively studied in computer architecture and VLSI for their energy, area, and latency benefits-offer a promising defense. Yet despite its success in machine learning accelerators, it remains underexplored for privacy-preserving FL. This work introduces variational approximate hardwareaware noise addition (VAHANA), a hardware-efficient method that integrates stochastic perturbations directly into the computation using approximate circuits and only 4 bits of uniform randomness, eliminating the need for Gaussian sampling or FP multiplication. We integrate VAHANA into the open-source RISC-V CV32E40P softcore using a hardware-software codesign approach, implementing custom instruction extensions that accelerate privacy-preserving operations with improved execution efficiency in both time and area. Evaluation on Kintex7 FPGA shows that VAHANA reduces memory footprint by 34% and reduces latency by up to 28.1×, while maintaining resilience against gradient inversion attacks on Medical MNIST, CIFAR10, and CIFAR-100 datasets.