Lune

ICLR2022Top-tier venue

Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models

Liam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum, Tom Goldstein

2022Year
181Citations
50Top-tier citations

Abstract

Federated learning has quickly gained popularity with its promises of increased user privacy and efficiency. Previous works have shown that federated gradient updates contain information that can be used to approximately recover user data in some situations. These previous attacks on user privacy have been limited in scope and do not scale to gradient updates aggregated over even a handful of data points, leaving some to conclude that data privacy is still intact for realistic training regimes. In this work, we introduce a new threat model based on minimal but malicious modifications of the shared model architecture which enable the server to directly obtain a verbatim copy of user data from gradient updates without solving difficult inverse problems. Even user data aggregated over large batcheswhere previous methods fail to extract meaningful content -can be reconstructed by these minimally modified models. * Authors contributed equally. Order chosen alphabetically.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 44626626-dd2e-465b-942c-d6a3bbab5391

Cited by top-tier papers50

Ask how each one uses it

Builds on7

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines