REVIEW 1 cited by
Reconstructing Training Data from Model Gradient, Provably
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Understanding when and how much a model gradient leaks information about the training sample is an important question in privacy. In this paper, we present a surprising result: even without training or memorizing the data, we can fully reconstruct the training samples from a single gradient query at a randomly chosen parameter value. We prove the identifiability of the training data under mild conditions: with shallow or deep neural networks and a wide range of activation functions. We also present a statistically and computationally efficient algorithm based on tensor decomposition to reconstruct the training data. As a provable attack that reveals sensitive training data, our findings suggest potential severe threats to privacy, especially in federated learning.
Forward citations
Cited by 1 Pith paper
-
Privacy Preserving Properties of Vision Classifiers
Using a self-built network inversion generator, the authors report SSIM-based reconstruction quality rankings across MNIST, FashionMNIST, SVHN, and CIFAR-10, finding MLP greater than ViT greater than CNN in memorizati...
Discussion (0). Continue with ORCID to comment.