Pith. sign in

REVIEW 3 cited by

SoK: On Gradient Leakage in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2404.05403 v2 pith:BRCZTPLQ submitted 2024-04-08 cs.CR cs.AI

classification cs.CRcs.AI
keywords giastextitpracticaltrainingeffectivenessmodelsettingssystems
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning (FL) facilitates collaborative model training among multiple clients without raw data exposure. However, recent studies have shown that clients' private training data can be reconstructed from shared gradients in FL, a vulnerability known as gradient inversion attacks (GIAs). While GIAs have demonstrated effectiveness under \emph{ideal settings and auxiliary assumptions}, their actual efficacy against \emph{practical FL systems} remains under-explored. To address this gap, we conduct a comprehensive study on GIAs in this work. We start with a survey of GIAs that establishes a timeline to trace their evolution and develops a systematization to uncover their inherent threats. By rethinking GIA in practical FL systems, three fundamental aspects influencing GIA's effectiveness are identified: \textit{training setup}, \textit{model}, and \textit{post-processing}. Guided by these aspects, we perform extensive theoretical and empirical evaluations of SOTA GIAs across diverse settings. Our findings highlight that GIA is notably \textit{constrained}, \textit{fragile}, and \textit{easily defensible}. Specifically, GIAs exhibit inherent limitations against practical local training settings. Additionally, their effectiveness is highly sensitive to the trained model, and even simple post-processing techniques applied to gradients can serve as effective defenses. Our work provides crucial insights into the limited threats of GIAs in practical FL systems. By rectifying prior misconceptions, we hope to inspire more accurate and realistic investigations on this topic.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings

    cs.LG 2025-06 conditional novelty 7.0 of 10

    FedLeak reconstructs high-fidelity images from federated learning gradients at practical batch sizes, without auxiliary data, by matching only the largest gradient components and regularizing the optimization.

  2. Images in Motion?: A First Look into Video Leakage in Collaborative Deep Learning

    cs.CV 2025-09 conditional novelty 6.0 of 10

    Gradient inversion recovers low-resolution frames from single-sample video gradients in federated learning, and super-resolution modestly improves fidelity against originals, while feature extractors resist the attack...

  3. Privacy-preserving Prompt Personalization in Federated Learning for Multimodal Large Language Models

    cs.CR 2025-05 conditional novelty 6.0 of 10

    SecFPP combines hierarchical prompt decomposition with secret-sharing-based adaptive clustering to protect user prompts in federated learning while preserving personalization accuracy.

Pith tools