REVIEW 4 cited by
Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Federated learning has quickly gained popularity with its promises of increased user privacy and efficiency. Previous works have shown that federated gradient updates contain information that can be used to approximately recover user data in some situations. These previous attacks on user privacy have been limited in scope and do not scale to gradient updates aggregated over even a handful of data points, leaving some to conclude that data privacy is still intact for realistic training regimes. In this work, we introduce a new threat model based on minimal but malicious modifications of the shared model architecture which enable the server to directly obtain a verbatim copy of user data from gradient updates without solving difficult inverse problems. Even user data aggregated over large batches -- where previous methods fail to extract meaningful content -- can be reconstructed by these minimally modified models.
Forward citations
Cited by 4 Pith papers
-
Federated Learning for Anomaly Detection in Energy Consumption Data: Assessing the Vulnerability to Adversarial Attacks
An empirical study of FGSM and PGD attacks on federated anomaly detection for smart meter data finds PGD more effective than FGSM, while the stated conclusion that FL is more vulnerable than centralized learning is co...
-
CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling
CENSOR defends federated learning against gradient inversion by transmitting a loss-optimized random gradient orthogonal to the true gradient, but its security claim is not established against adaptive adversaries.
-
Privacy Leakage in Federated Learning in Radiology Reports: A Comparative Evaluation of Tokenizer-Driven Privacy Risks
Up to 44% of radiology report sentences were exactly reconstructed from federated-learning gradients in this worst-case attack, with the RadBERT tokenizer leaking the most—but the paper's own re-run did not reproduce ...
-
A Survey of Secure Semantic Communications
A comprehensive survey of security and privacy challenges in semantic communication, categorized by the SemCom life cycle and paired with available defense technologies.
Discussion (0). Continue with ORCID to comment.