Pith. sign in

REVIEW 3 cited by

A Framework for Evaluating Gradient Leakage Attacks in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2004.10397 v2 pith:UHPC3OUQ submitted 2020-04-22 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords clientfederatedlocalattackframeworkleakagelearningprivacy
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning (FL) is an emerging distributed machine learning framework for collaborative model training with a network of clients (edge devices). FL offers default client privacy by allowing clients to keep their sensitive data on local devices and to only share local training parameter updates with the federated server. However, recent studies have shown that even sharing local parameter updates from a client to the federated server may be susceptible to gradient leakage attacks and intrude the client privacy regarding its training data. In this paper, we present a principled framework for evaluating and comparing different forms of client privacy leakage attacks. We first provide formal and experimental analysis to show how adversaries can reconstruct the private local training data by simply analyzing the shared parameter update from local training (e.g., local gradient or weight update vector). We then analyze how different hyperparameter configurations in federated learning and different settings of the attack algorithm may impact on both attack effectiveness and attack cost. Our framework also measures, evaluates, and analyzes the effectiveness of client privacy leakage attacks under different gradient compression ratios when using communication efficient FL protocols. Our experiments also include some preliminary mitigation strategies to highlight the importance of providing a systematic attack evaluation framework towards an in-depth understanding of the various forms of client privacy leakage threats in federated learning and developing theoretical foundations for attack mitigation.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings

    cs.LG 2025-06 conditional novelty 7.0 of 10

    FedLeak reconstructs high-fidelity images from federated learning gradients at practical batch sizes, without auxiliary data, by matching only the largest gradient components and regularizing the optimization.

  2. Gradient Inversion Transcript: Leveraging Robust Generative Priors to Reconstruct Training Data from Gradient Leakage

    cs.LG 2025-05 conditional novelty 5.0 of 10

    GIT adaptively structures a generative model to invert backpropagation, reconstructing training data from leaked gradients more accurately and robustly than existing methods.

  3. Efficient Privacy-Preserving Cross-Silo Federated Learning with Multi-Key Homomorphic Encryption

    cs.CR 2025-05 conditional novelty 4.0 of 10

    MASER combines majority-vote weight pruning with multi-key homomorphic encryption to reduce privacy-preserving federated learning overhead by 3 to 8 times while keeping accuracy within about 1 percent of vanilla FL.

Pith tools