{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:IHJPJQDXUEBHPYZJM4ERU2TPX3","short_pith_number":"pith:IHJPJQDX","schema_version":"1.0","canonical_sha256":"41d2f4c077a10277e32967091a6a6fbefecfbb26fe5a3e4608d3e812e852b4a1","source":{"kind":"arxiv","id":"2406.15731","version":1},"attestation_state":"computed","paper":{"title":"Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Jiacheng Du, Jiahui Hu, Kui Ren, Xiaoyi Pang, Yongle Chen, Zhibo Wang, Zhiwei Chang","submitted_at":"2024-06-22T04:42:18Z","abstract_excerpt":"Federated Learning (FL) exhibits privacy vulnerabilities under gradient inversion attacks (GIAs), which can extract private information from individual gradients. To enhance privacy, FL incorporates Secure Aggregation (SA) to prevent the server from obtaining individual gradients, thus effectively resisting GIAs. In this paper, we propose a stealthy label inference attack to bypass SA and recover individual clients' private labels. Specifically, we conduct a theoretical analysis of label inference from the aggregated gradients that are exclusively obtained after implementing SA. The analysis r"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2406.15731","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-06-22T04:42:18Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"7939122979fa6d4f645db6a81e0205b6cf22de6586d7fa27c4ad65a14d563136","abstract_canon_sha256":"e4a3bde61ad0a91de3586ed0b9ab6f8dbb67bdf2b9d9514271a1e26589bea6fc"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:35:26.723063Z","signature_b64":"ITARmSiY/boO+JGM8y/4wwkGR0+gLzFEBF3rGtVt9WoZpatORqBzGkerGMj1bM2KSz6psu+YwwlU1ZBiSRaWDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"41d2f4c077a10277e32967091a6a6fbefecfbb26fe5a3e4608d3e812e852b4a1","last_reissued_at":"2026-07-05T08:35:26.722646Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:35:26.722646Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Jiacheng Du, Jiahui Hu, Kui Ren, Xiaoyi Pang, Yongle Chen, Zhibo Wang, Zhiwei Chang","submitted_at":"2024-06-22T04:42:18Z","abstract_excerpt":"Federated Learning (FL) exhibits privacy vulnerabilities under gradient inversion attacks (GIAs), which can extract private information from individual gradients. To enhance privacy, FL incorporates Secure Aggregation (SA) to prevent the server from obtaining individual gradients, thus effectively resisting GIAs. In this paper, we propose a stealthy label inference attack to bypass SA and recover individual clients' private labels. Specifically, we conduct a theoretical analysis of label inference from the aggregated gradients that are exclusively obtained after implementing SA. The analysis r"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2406.15731","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2406.15731/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2406.15731","created_at":"2026-07-05T08:35:26.722702+00:00"},{"alias_kind":"arxiv_version","alias_value":"2406.15731v1","created_at":"2026-07-05T08:35:26.722702+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2406.15731","created_at":"2026-07-05T08:35:26.722702+00:00"},{"alias_kind":"pith_short_12","alias_value":"IHJPJQDXUEBH","created_at":"2026-07-05T08:35:26.722702+00:00"},{"alias_kind":"pith_short_16","alias_value":"IHJPJQDXUEBHPYZJ","created_at":"2026-07-05T08:35:26.722702+00:00"},{"alias_kind":"pith_short_8","alias_value":"IHJPJQDX","created_at":"2026-07-05T08:35:26.722702+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.02958","citing_title":"Echelon: Auditable Aggregate-Only Language-Model Adaptation Across Privacy Boundaries","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2506.06742","citing_title":"LADSG: Label-Anonymized Distillation and Similar Gradient Substitution for Label Privacy in Vertical Federated Learning","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2603.09002","citing_title":"Security Considerations for Multi-agent Systems","ref_index":183,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3","json":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3.json","graph_json":"https://pith.science/api/pith-number/IHJPJQDXUEBHPYZJM4ERU2TPX3/graph.json","events_json":"https://pith.science/api/pith-number/IHJPJQDXUEBHPYZJM4ERU2TPX3/events.json","paper":"https://pith.science/paper/IHJPJQDX"},"agent_actions":{"view_html":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3","download_json":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3.json","view_paper":"https://pith.science/paper/IHJPJQDX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2406.15731&json=true","fetch_graph":"https://pith.science/api/pith-number/IHJPJQDXUEBHPYZJM4ERU2TPX3/graph.json","fetch_events":"https://pith.science/api/pith-number/IHJPJQDXUEBHPYZJM4ERU2TPX3/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3/action/timestamp_anchor","attest_storage":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3/action/storage_attestation","attest_author":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3/action/author_attestation","sign_citation":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3/action/citation_signature","submit_replication":"https://pith.science/pith/IHJPJQDXUEBHPYZJM4ERU2TPX3/action/replication_record"}},"created_at":"2026-07-05T08:35:26.722702+00:00","updated_at":"2026-07-05T08:35:26.722702+00:00"}