REVIEW 3 cited by
Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Federated learning (FL) has rapidly risen in popularity due to its promise of privacy and efficiency. Previous works have exposed privacy vulnerabilities in the FL pipeline by recovering user data from gradient updates. However, existing attacks fail to address realistic settings because they either 1) require toy settings with very small batch sizes, or 2) require unrealistic and conspicuous architecture modifications. We introduce a new strategy that dramatically elevates existing attacks to operate on batches of arbitrarily large size, and without architectural modifications. Our model-agnostic strategy only requires modifications to the model parameters sent to the user, which is a realistic threat model in many scenarios. We demonstrate the strategy in challenging large-scale settings, obtaining high-fidelity data extraction in both cross-device and cross-silo federated learning.
Forward citations
Cited by 3 Pith papers
-
CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling
CENSOR defends federated learning against gradient inversion by transmitting a loss-optimized random gradient orthogonal to the true gradient, but its security claim is not established against adaptive adversaries.
-
Gradient Inversion Attack on Graph Neural Networks
GLG reconstructs node features and graph structure from GNN gradients in federated learning, achieving near-perfect recovery for GraphSAGE and high accuracy for GCN under per-node gradient threat models.
-
Hidden Data Privacy Breaches in Federated Learning
A malicious federated learning server can hide a secret model inside client parameters via code injection and later reconstruct the client's training images from Fibonacci-coded index queries.
Discussion (0). Continue with ORCID to comment.