Pith. sign in

REVIEW 4 cited by

Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2110.13057 v2 pith:O6FYZZQ4 submitted 2021-10-25 cs.LG cs.CR

classification cs.LGcs.CR
keywords datauserfederatedgradientpreviousprivacyupdatesaggregated
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning has quickly gained popularity with its promises of increased user privacy and efficiency. Previous works have shown that federated gradient updates contain information that can be used to approximately recover user data in some situations. These previous attacks on user privacy have been limited in scope and do not scale to gradient updates aggregated over even a handful of data points, leaving some to conclude that data privacy is still intact for realistic training regimes. In this work, we introduce a new threat model based on minimal but malicious modifications of the shared model architecture which enable the server to directly obtain a verbatim copy of user data from gradient updates without solving difficult inverse problems. Even user data aggregated over large batches -- where previous methods fail to extract meaningful content -- can be reconstructed by these minimally modified models.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Federated Learning for Anomaly Detection in Energy Consumption Data: Assessing the Vulnerability to Adversarial Attacks

    cs.LG 2025-02 reject novelty 6.0 of 10

    An empirical study of FGSM and PGD attacks on federated anomaly detection for smart meter data finds PGD more effective than FGSM, while the stated conclusion that FL is more vulnerable than centralized learning is co...

  2. CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling

    cs.LG 2025-01 reject novelty 6.0 of 10

    CENSOR defends federated learning against gradient inversion by transmitting a loss-optimized random gradient orthogonal to the true gradient, but its security claim is not established against adaptive adversaries.

  3. Privacy Leakage in Federated Learning in Radiology Reports: A Comparative Evaluation of Tokenizer-Driven Privacy Risks

    cs.LG 2026-07 reject novelty 5.0 of 10

    Up to 44% of radiology report sentences were exactly reconstructed from federated-learning gradients in this worst-case attack, with the RadBERT tokenizer leaking the most—but the paper's own re-run did not reproduce ...

  4. A Survey of Secure Semantic Communications

    cs.CR 2025-01 conditional novelty 3.0 of 10

    A comprehensive survey of security and privacy challenges in semantic communication, categorized by the SemCom life cycle and paired with available defense technologies.

Pith tools