Pith. sign in

REVIEW 9 cited by

Deep Leakage from Gradients

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1906.08935 v2 pith:E3RAJHCV submitted 2019-06-21 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords gradientgradientsleakagedeeptrainingdatalearningmethod
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Exchanging gradients is a widely used method in modern multi-node machine learning system (e.g., distributed training, collaborative learning). For a long time, people believed that gradients are safe to share: i.e., the training data will not be leaked by gradient exchange. However, we show that it is possible to obtain the private training data from the publicly shared gradients. We name this leakage as Deep Leakage from Gradient and empirically validate the effectiveness on both computer vision and natural language processing tasks. Experimental results show that our attack is much stronger than previous approaches: the recovery is pixel-wise accurate for images and token-wise matching for texts. We want to raise people's awareness to rethink the gradient's safety. Finally, we discuss several possible strategies to prevent such deep leakage. The most effective defense method is gradient pruning.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 9 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Numerical Gradient Inversion Attack in Variational Quantum Neural-Networks

    cs.LG 2025-04 conditional novelty 6.0 of 10

    A finite-difference gradient inversion attack with adaptive low-pass filtering and Kalman acceleration reconstructs training inputs of small variational quantum neural networks from shared gradients when the model is ...

  2. Privacy Leakage in Federated Learning in Radiology Reports: A Comparative Evaluation of Tokenizer-Driven Privacy Risks

    cs.LG 2026-07 reject novelty 5.0 of 10

    Up to 44% of radiology report sentences were exactly reconstructed from federated-learning gradients in this worst-case attack, with the RadBERT tokenizer leaking the most—but the paper's own re-run did not reproduce ...

  3. FedRP: A Communication-Efficient Approach for Differentially Private Federated Learning Using Random Projection

    cs.LG 2025-09 reject novelty 5.0 of 10

    FedRP claims to preserve FedAvg-level accuracy while sending only a few numbers per client per round and providing an (epsilon, delta)-DP guarantee.

  4. Privacy Preserving Conversion Modeling in Data Clean Room

    cs.LG 2025-05 conditional novelty 5.0 of 10

    Batch-level aggregated gradients, LoRA adapters, and de-biased label differential privacy let advertisers and platforms train conversion models in a clean room with modest AUC loss and much lower communication cost.

  5. SMTFL: Secure Model Training to Untrusted Participants in Federated Learning

    cs.CR 2025-02 reject novelty 5.0 of 10

    An FL scheme combining client grouping, gradient splitting, performance-based malicious detection, and threshold encryption aims to resist gradient inversion and poisoning attacks, claiming over 95% malicious-client l...

  6. Large Language Model Adversarial Landscape Through the Lens of Attack Objectives

    cs.CR 2025-02 conditional novelty 4.0 of 10

    A survey that re-frames LLM adversarial attacks and defenses around four attacker objectives: privacy, integrity, availability, and misuse.

  7. BlindFL: Segmented Federated Learning with Fully Homomorphic Encryption

    cs.CR 2025-01 conditional novelty 4.0 of 10

    BlindFL randomly selects and encrypts a subset of each client's model layers for aggregation, cutting fully homomorphic encryption overhead in federated learning while preserving accuracy and reducing client-side grad...

  8. Fed-AugMix: Balancing Privacy and Utility via Data Augmentation

    cs.CR 2024-12 conditional novelty 4.0 of 10

    Fed-AugMix applies AugMix data augmentation with a Jensen-Shannon consistency loss at federated clients, empirically degrading gradient-inversion reconstruction quality while preserving or improving model accuracy.

  9. LLM Security: Vulnerabilities, Attacks, Defenses, and Countermeasures

    cs.CR 2025-05 conditional novelty 3.0 of 10

    This survey categorizes attacks on large language models by lifecycle phase and maps them to prevention and detection defenses, concluding that only a few defenses are highly effective.

Pith tools