Pith. sign in

REVIEW 4 cited by

Inverting Gradients -- How easy is it to break privacy in federated learning?

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2003.14053 v2 pith:YCXPKOV3 submitted 2020-03-31 cs.CV cs.CRcs.LG

classification cs.CVcs.CRcs.LG
keywords gradientsparameterprivacyevenfederatedinputlearningonly
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The idea of federated learning is to collaboratively train a neural network on a server. Each user receives the current weights of the network and in turns sends parameter updates (gradients) based on local data. This protocol has been designed not only to train neural networks data-efficiently, but also to provide privacy benefits for users, as their input data remains on device and only parameter gradients are shared. But how secure is sharing parameter gradients? Previous attacks have provided a false sense of security, by succeeding only in contrived settings - even for a single image. However, by exploiting a magnitude-invariant loss along with optimization strategies based on adversarial attacks, we show that is is actually possible to faithfully reconstruct images at high resolution from the knowledge of their parameter gradients, and demonstrate that such a break of privacy is possible even for trained deep networks. We analyze the effects of architecture as well as parameters on the difficulty of reconstructing an input image and prove that any input to a fully connected layer can be reconstructed analytically independent of the remaining architecture. Finally we discuss settings encountered in practice and show that even averaging gradients over several iterations or several images does not protect the user's privacy in federated learning applications in computer vision.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. TriShield: Zero-Utility-Loss Defense Against Privacy Backdoors in Federated Language Model Fine-Tuning via Orthogonal Gradient Projection and Optimizer State Entanglement

    cs.LG 2026-07 reject novelty 6.0 of 10

    TriShield combines artifact detection, Adam momentum pre-entanglement, and SVD task-subspace projection to drive NeuroImprint reconstruction to 0% with claimed near-zero utility loss.

  2. Privacy Leakage in Federated Learning in Radiology Reports: A Comparative Evaluation of Tokenizer-Driven Privacy Risks

    cs.LG 2026-07 reject novelty 5.0 of 10

    Up to 44% of radiology report sentences were exactly reconstructed from federated-learning gradients in this worst-case attack, with the RadBERT tokenizer leaking the most—but the paper's own re-run did not reproduce ...

  3. BlindFL: Segmented Federated Learning with Fully Homomorphic Encryption

    cs.CR 2025-01 conditional novelty 4.0 of 10

    BlindFL randomly selects and encrypts a subset of each client's model layers for aggregation, cutting fully homomorphic encryption overhead in federated learning while preserving accuracy and reducing client-side grad...

  4. Fed-AugMix: Balancing Privacy and Utility via Data Augmentation

    cs.CR 2024-12 conditional novelty 4.0 of 10

    Fed-AugMix applies AugMix data augmentation with a Jensen-Shannon consistency loss at federated clients, empirically degrading gradient-inversion reconstruction quality while preserving or improving model accuracy.

Pith tools