Pith. sign in

REVIEW 1 cited by

Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2406.15731 v1 pith:IHJPJQDX submitted 2024-06-22 cs.CR cs.AI

classification cs.CRcs.AI
keywords gradientslabelindividualaggregatedembeddingslogitsmodelaggregation
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated Learning (FL) exhibits privacy vulnerabilities under gradient inversion attacks (GIAs), which can extract private information from individual gradients. To enhance privacy, FL incorporates Secure Aggregation (SA) to prevent the server from obtaining individual gradients, thus effectively resisting GIAs. In this paper, we propose a stealthy label inference attack to bypass SA and recover individual clients' private labels. Specifically, we conduct a theoretical analysis of label inference from the aggregated gradients that are exclusively obtained after implementing SA. The analysis results reveal that the inputs (embeddings) and outputs (logits) of the final fully connected layer (FCL) contribute to gradient disaggregation and label restoration. To preset the embeddings and logits of FCL, we craft a fishing model by solely modifying the parameters of a single batch normalization (BN) layer in the original model. Distributing client-specific fishing models, the server can derive the individual gradients regarding the bias of FCL by resolving a linear system with expected embeddings and the aggregated gradients as coefficients. Then the labels of each client can be precisely computed based on preset logits and gradients of FCL's bias. Extensive experiments show that our attack achieves large-scale label recovery with 100\% accuracy on various datasets and model architectures.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings

    cs.LG 2025-06 conditional novelty 7.0 of 10

    FedLeak reconstructs high-fidelity images from federated learning gradients at practical batch sizes, without auxiliary data, by matching only the largest gradient components and regularizing the optimization.

Pith tools