Pith. sign in

REVIEW 1 cited by

Privacy Attacks in Decentralized Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2402.10001 v2 pith:ZJ52TW7T submitted 2024-02-15 cs.LG cs.CR

classification cs.LGcs.CR
keywords usersattackd-gddatagraphattackersaveragingdecentralized
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Decentralized Gradient Descent (D-GD) allows a set of users to perform collaborative learning without sharing their data by iteratively averaging local model updates with their neighbors in a network graph. The absence of direct communication between non-neighbor nodes might lead to the belief that users cannot infer precise information about the data of others. In this work, we demonstrate the opposite, by proposing the first attack against D-GD that enables a user (or set of users) to reconstruct the private data of other users outside their immediate neighborhood. Our approach is based on a reconstruction attack against the gossip averaging protocol, which we then extend to handle the additional challenges raised by D-GD. We validate the effectiveness of our attack on real graphs and datasets, showing that the number of users compromised by a single or a handful of attackers is often surprisingly large. We empirically investigate some of the factors that affect the performance of the attack, namely the graph topology, the number of attackers, and their position in the graph.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Dropout-Robust Mechanisms for Differentially Private and Fully Decentralized Mean Estimation

    cs.CR 2025-06 conditional novelty 7.0 of 10

    IncA is a fully decentralized, differentially private mean-estimation protocol whose correlated noise cancels in the no-dropout case, achieving central-DP accuracy under a strong adversarial model.

Pith tools