Pith. sign in

REVIEW 3 cited by

Label Leakage and Protection from Forward Embedding in Vertical Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2203.01451 v3 pith:UBAIPV3T submitted 2022-03-02 cs.LG cs.CR

classification cs.LGcs.CR
keywords labelembeddingleakageintermediatelabelsgradientsworkbackpropagated
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Vertical federated learning (vFL) has gained much attention and been deployed to solve machine learning problems with data privacy concerns in recent years. However, some recent work demonstrated that vFL is vulnerable to privacy leakage even though only the forward intermediate embedding (rather than raw features) and backpropagated gradients (rather than raw labels) are communicated between the involved participants. As the raw labels often contain highly sensitive information, some recent work has been proposed to prevent the label leakage from the backpropagated gradients effectively in vFL. However, these work only identified and defended the threat of label leakage from the backpropagated gradients. None of these work has paid attention to the problem of label leakage from the intermediate embedding. In this paper, we propose a practical label inference method which can steal private labels effectively from the shared intermediate embedding even though some existing protection methods such as label differential privacy and gradients perturbation are applied. The effectiveness of the label attack is inseparable from the correlation between the intermediate embedding and corresponding private labels. To mitigate the issue of label leakage from the forward embedding, we add an additional optimization goal at the label party to limit the label stealing ability of the adversary by minimizing the distance correlation between the intermediate embedding and corresponding private labels. We conducted massive experiments to demonstrate the effectiveness of our proposed protection methods.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. HASSLE: A Self-Supervised Learning Enhanced Hijacking Attack on Vertical Federated Learning

    cs.CR 2025-07 conditional novelty 6.0 of 10

    HASSLE combines gradient-based label inference with self-supervised pretraining and adversarial embeddings to hijack vertical federated learning models, achieving over 99% attack success on four datasets and 85% on CIFAR-100.

  2. Multimodal Federated Learning: A Survey through the Lens of Different FL Paradigms

    cs.LG 2025-05 conditional novelty 5.0 of 10

    A paradigm-based taxonomy of multimodal federated learning that assigns each branch a headline challenge: modality heterogeneity (horizontal), privacy leakage (vertical), and efficiency (hybrid).

  3. Privacy Preserving Conversion Modeling in Data Clean Room

    cs.LG 2025-05 conditional novelty 5.0 of 10

    Batch-level aggregated gradients, LoRA adapters, and de-biased label differential privacy let advertisers and platforms train conversion models in a clean room with modest AUC loss and much lower communication cost.

Pith tools