Pith. sign in

Reconstructing Training Data from Model Gradient, Provably

1 Pith paper cite this work. Polarity classification is still indexing.

1 Pith paper citing it
abstract

Understanding when and how much a model gradient leaks information about the training sample is an important question in privacy. In this paper, we present a surprising result: even without training or memorizing the data, we can fully reconstruct the training samples from a single gradient query at a randomly chosen parameter value. We prove the identifiability of the training data under mild conditions: with shallow or deep neural networks and a wide range of activation functions. We also present a statistically and computationally efficient algorithm based on tensor decomposition to reconstruct the training data. As a provable attack that reveals sensitive training data, our findings suggest potential severe threats to privacy, especially in federated learning.

citation-role summary

background 1

citation-polarity summary

fields

cs.LG 1

years

2025 1

verdicts

REJECT 1

roles

background 1

polarities

support 1

representative citing papers

Privacy Preserving Properties of Vision Classifiers

cs.LG · 2025-02-02 · reject · novelty 4.0

Using a self-built network inversion generator, the authors report SSIM-based reconstruction quality rankings across MNIST, FashionMNIST, SVHN, and CIFAR-10, finding MLP greater than ViT greater than CNN in memorization, but with no statistical support.

citing papers explorer

Showing 1 of 1 citing paper.

  • Privacy Preserving Properties of Vision Classifiers cs.LG · 2025-02-02 · reject · none · ref 19 · internal anchor

    Using a self-built network inversion generator, the authors report SSIM-based reconstruction quality rankings across MNIST, FashionMNIST, SVHN, and CIFAR-10, finding MLP greater than ViT greater than CNN in memorization, but with no statistical support.