Pith. sign in

REVIEW 4 cited by

Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2201.12675 v2 pith:Z4XTSAFD submitted 2022-01-29 cs.LG cs.CLcs.CR

classification cs.LGcs.CLcs.CR
keywords privacytextattacksuserattackfederatedlearningmodels
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

A central tenet of Federated learning (FL), which trains models without centralizing user data, is privacy. However, previous work has shown that the gradient updates used in FL can leak user information. While the most industrial uses of FL are for text applications (e.g. keystroke prediction), nearly all attacks on FL privacy have focused on simple image classifiers. We propose a novel attack that reveals private user text by deploying malicious parameter vectors, and which succeeds even with mini-batches, multiple users, and long sequences. Unlike previous attacks on FL, the attack exploits characteristics of both the Transformer architecture and the token embedding, separately extracting tokens and positional embeddings to retrieve high-fidelity text. This work suggests that FL on text, which has historically been resistant to privacy attacks, is far more vulnerable than previously thought.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. AnalogFed: Privacy-Preserving Discovery of Analog Circuits at Scale with Federated Generative AI

    cs.LG 2025-07 reject novelty 6.0 of 10

    AnalogFed combines federated learning with a generative analog-topology model, adding dummy-token input perturbation and partial homomorphic encryption to resist membership inference and model inversion attacks.

  2. Gradient Inversion Attack on Graph Neural Networks

    cs.LG 2024-11 conditional novelty 5.0 of 10

    GLG reconstructs node features and graph structure from GNN gradients in federated learning, achieving near-perfect recovery for GraphSAGE and high accuracy for GCN under per-node gradient threat models.

  3. Hidden Data Privacy Breaches in Federated Learning

    cs.CL 2024-11 conditional novelty 5.0 of 10

    A malicious federated learning server can hide a secret model inside client parameters via code injection and later reconstruct the client's training images from Fibonacci-coded index queries.

  4. Trustformer: A Trusted Federated Transformer

    cs.LG 2025-01 reject novelty 4.0 of 10

    A federated Transformer training method that transmits k-means centroids instead of weights, but whose convergence proof is flawed and privacy claim is unsupported.

Pith tools