Pith. sign in

REVIEW 3 cited by

Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2202.00580 v2 pith:PMZI5WS6 submitted 2022-02-01 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords datafederatedlearningmodificationssettingsstrategyuserattacks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning (FL) has rapidly risen in popularity due to its promise of privacy and efficiency. Previous works have exposed privacy vulnerabilities in the FL pipeline by recovering user data from gradient updates. However, existing attacks fail to address realistic settings because they either 1) require toy settings with very small batch sizes, or 2) require unrealistic and conspicuous architecture modifications. We introduce a new strategy that dramatically elevates existing attacks to operate on batches of arbitrarily large size, and without architectural modifications. Our model-agnostic strategy only requires modifications to the model parameters sent to the user, which is a realistic threat model in many scenarios. We demonstrate the strategy in challenging large-scale settings, obtaining high-fidelity data extraction in both cross-device and cross-silo federated learning.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling

    cs.LG 2025-01 reject novelty 6.0 of 10

    CENSOR defends federated learning against gradient inversion by transmitting a loss-optimized random gradient orthogonal to the true gradient, but its security claim is not established against adaptive adversaries.

  2. Gradient Inversion Attack on Graph Neural Networks

    cs.LG 2024-11 conditional novelty 5.0 of 10

    GLG reconstructs node features and graph structure from GNN gradients in federated learning, achieving near-perfect recovery for GraphSAGE and high accuracy for GCN under per-node gradient threat models.

  3. Hidden Data Privacy Breaches in Federated Learning

    cs.CL 2024-11 conditional novelty 5.0 of 10

    A malicious federated learning server can hide a secret model inside client parameters via code injection and later reconstruct the client's training images from Fibonacci-coded index queries.

Pith tools