Pith. sign in

REVIEW 5 cited by

Deep Leakage from Gradients

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1906.08935 v2 pith:E3RAJHCV submitted 2019-06-21 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords gradientgradientsleakagedeeptrainingdatalearningmethod
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Exchanging gradients is a widely used method in modern multi-node machine learning system (e.g., distributed training, collaborative learning). For a long time, people believed that gradients are safe to share: i.e., the training data will not be leaked by gradient exchange. However, we show that it is possible to obtain the private training data from the publicly shared gradients. We name this leakage as Deep Leakage from Gradient and empirically validate the effectiveness on both computer vision and natural language processing tasks. Experimental results show that our attack is much stronger than previous approaches: the recovery is pixel-wise accurate for images and token-wise matching for texts. We want to raise people's awareness to rethink the gradient's safety. Finally, we discuss several possible strategies to prevent such deep leakage. The most effective defense method is gradient pruning.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Privacy Leakage in Federated Learning in Radiology Reports: A Comparative Evaluation of Tokenizer-Driven Privacy Risks

    cs.LG 2026-07 reject novelty 5.0 of 10

    Up to 44% of radiology report sentences were exactly reconstructed from federated-learning gradients in this worst-case attack, with the RadBERT tokenizer leaking the most—but the paper's own re-run did not reproduce ...

  2. FedRP: A Communication-Efficient Approach for Differentially Private Federated Learning Using Random Projection

    cs.LG 2025-09 reject novelty 5.0 of 10

    FedRP claims to preserve FedAvg-level accuracy while sending only a few numbers per client per round and providing an (epsilon, delta)-DP guarantee.

  3. Privacy Preserving Conversion Modeling in Data Clean Room

    cs.LG 2025-05 conditional novelty 5.0 of 10

    Batch-level aggregated gradients, LoRA adapters, and de-biased label differential privacy let advertisers and platforms train conversion models in a clean room with modest AUC loss and much lower communication cost.

  4. SMTFL: Secure Model Training to Untrusted Participants in Federated Learning

    cs.CR 2025-02 reject novelty 5.0 of 10

    An FL scheme combining client grouping, gradient splitting, performance-based malicious detection, and threshold encryption aims to resist gradient inversion and poisoning attacks, claiming over 95% malicious-client l...

  5. Large Language Model Adversarial Landscape Through the Lens of Attack Objectives

    cs.CR 2025-02 conditional novelty 4.0 of 10

    A survey that re-frames LLM adversarial attacks and defenses around four attacker objectives: privacy, integrity, availability, and misuse.

Pith tools