Pith. sign in

REVIEW 1 cited by

Reconstructing Training Data from Model Gradient, Provably

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2212.03714 v3 pith:SXWCHEH7 submitted 2022-12-07 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords trainingdatagradientmodelprivacyreconstructactivationalgorithm
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Understanding when and how much a model gradient leaks information about the training sample is an important question in privacy. In this paper, we present a surprising result: even without training or memorizing the data, we can fully reconstruct the training samples from a single gradient query at a randomly chosen parameter value. We prove the identifiability of the training data under mild conditions: with shallow or deep neural networks and a wide range of activation functions. We also present a statistically and computationally efficient algorithm based on tensor decomposition to reconstruct the training data. As a provable attack that reveals sensitive training data, our findings suggest potential severe threats to privacy, especially in federated learning.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Privacy Preserving Properties of Vision Classifiers

    cs.LG 2025-02 reject novelty 4.0 of 10

    Using a self-built network inversion generator, the authors report SSIM-based reconstruction quality rankings across MNIST, FashionMNIST, SVHN, and CIFAR-10, finding MLP greater than ViT greater than CNN in memorizati...

Pith tools