Pith. sign in

REVIEW 1 cited by

SPEAR:Exact Gradient Inversion of Batches in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2403.03945 v3 pith:67EU6WAH submitted 2024-03-06 cs.LG cs.CRcs.DC

classification cs.LGcs.CRcs.DC
keywords batchesgradientlearningonlyreconstructionspearalgorithmattacks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Federated learning is a framework for collaborative machine learning where clients only share gradient updates and not their private data with a server. However, it was recently shown that gradient inversion attacks can reconstruct this data from the shared gradients. In the important honest-but-curious setting, existing attacks enable exact reconstruction only for batch size of $b=1$, with larger batches permitting only approximate reconstruction. In this work, we propose SPEAR, the first algorithm reconstructing whole batches with $b >1$ exactly. SPEAR combines insights into the explicit low-rank structure of gradients with a sampling-based algorithm. Crucially, we leverage ReLU-induced gradient sparsity to precisely filter out large numbers of incorrect samples, making a final reconstruction step tractable. We provide an efficient GPU implementation for fully connected networks and show that it recovers high-dimensional ImageNet inputs in batches of up to $b \lesssim 25$ exactly while scaling to large networks. Finally, we show theoretically that much larger batches can be reconstructed with high probability given exponential time.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. DRAUN: An Algorithm-Agnostic Data Reconstruction Attack on Federated Unlearning Systems

    cs.LG 2025-06 conditional novelty 6.0 of 10

    DRAUN reconstructs unlearned client images from federated unlearning updates by simulating possible unlearning losses and matching gradients, exposing privacy leakage in optimization-based federated unlearning.

Pith tools