SPEAR: Exact Gradient Inversion of Batches in Federated Learning
Dimitar I. Dimitrov, Maximilian Baader, Mark Niklas Müller, Martin T. Vechev
Abstract
Federated learning is a framework for collaborative machine learning where clients only share gradient updates and not their private data with a server. However, it was recently shown that gradient inversion attacks can reconstruct this data from the shared gradients. In the important honest-but-curious setting, existing attacks enable exact reconstruction only for batch size of , with larger batches permitting only approximate reconstruction. In this work, we propose SPEAR, the first algorithm reconstructing whole batches with exactly. SPEAR combines insights into the explicit low-rank structure of gradients with a sampling-based algorithm. Crucially, we leverage ReLU-induced gradient sparsity to precisely filter out large numbers of incorrect samples, making a final reconstruction step tractable. We provide an efficient GPU implementation for fully connected networks and show that it recovers high-dimensional ImageNet inputs in batches of up to exactly while scaling to large networks. Finally, we show theoretically that much larger batches can be reconstructed with high probability given exponential time.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2bfb278c-d132-45c5-895b-7001639090f4Cited by top-tier papers2
- Shared Spotlight Meridian: Distributed Sparse Pseudorandom Functions for Scalable Federated LearningYoulong Ding, Peihua Mai, Jingqi Zhang, Sherman S. M. Chow et al.S&P 2026 · 1 citation
- When the Aggregator Cheats: Data-Free Backdoors in Federated LLM-based QA SystemsChenqing Zhu, Yanbo Dai, Yulong Tian, Qingming Li et al.USENIX Security 2026
Builds on13
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified ModelsLiam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum et al.ICLR 2022 · 181 citations
- R-GAP: Recursive Gradient Attack on PrivacyJunyi Zhu, Matthew B. BlaschkoICLR 2021 · 157 citations
- Recovering Private Text in Federated Learning of Language ModelsSamyak Gupta, Yangsibo Huang, Zexuan Zhong, Tianyu Gao et al.NeurIPS 2022 · 120 citations
Related papers
- DAGER: Exact Gradient Inversion for Large Language ModelsIvo Petrov, Dimitar I. Dimitrov, Maximilian Baader, Mark Niklas Müller et al.NeurIPS 2024 · 29 citations
- GRAIN: Exact Graph Reconstruction from GradientsMaria Drencheva, Ivo Petrov, Maximilian Baader, Dimitar Iliev Dimitrov et al.ICLR 2025
- ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning Through Activation RecoveryZirui Gong, Leo Yu Zhang, Yanjun Zhang, Viet Vo et al.S&P 2026
- Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component AnalysisSanjay Kariyappa, Chuan Guo, Kiwan Maeng, Wenjie Xiong et al.ICML 2023 · 43 citations
- See Through Gradients: Image Batch Recovery via GradInversionHongxu Yin, Arun Mallya, Arash Vahdat, José M. Álvarez et al.CVPR 2021
