Privacy Attacks in Decentralized Learning
Abdellah El Mrini, Edwige Cyffers, Aurélien Bellet
Abstract
Decentralized Gradient Descent (D-GD) allows a set of users to perform collaborative learning without sharing their data by iteratively averaging local model updates with their neighbors in a network graph. The absence of direct communication between non-neighbor nodes might lead to the belief that users cannot infer precise information about the data of others. In this work, we demonstrate the opposite, by proposing the first attack against D-GD that enables a user (or set of users) to reconstruct the private data of other users outside their immediate neighborhood. Our approach is based on a reconstruction attack against the gossip averaging protocol, which we then extend to handle the additional challenges raised by D-GD. We validate the effectiveness of our attack on real graphs and datasets, showing that the number of users compromised by a single or a handful of attackers is often surprisingly large. We empirically investigate some of the factors that affect the performance of the attack, namely the graph topology, the number of attackers, and their position in the graph. Our code is available at https://github.com/AbdellahElmrini/decAttack .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 68ba5004-f1a4-4612-86c9-c19fb2bf216fCited by top-tier papers5
- Unified Privacy Guarantees for Decentralized Learning via Matrix FactorizationAurélien Bellet, Edwige Cyffers, Davide Frey, Romaric Gaudel et al.ICLR 2026 · 3 citations
- On The Surprising Effectiveness of a Single Global Merging in Decentralized LearningTongtian Zhu, Tianyu Zhang, Mingze Wang, Zhanpeng Zhou et al.ICLR 2026 · 2 citations
- Differentially Private Equilibrium Finding in Polymatrix GamesMingyang Liu, Gabriele Farina, Asuman OzdaglarICLR 2026 · 1 citation
- When Topology Betrays Privacy: Lattice-Based Reconstruction Attacks on Secure Aggregation in Decentralized Federated LearningWenrui Yu, Changlong Ji, Johannes Bjerva, Qiongxiu LiCCS 2026
- DICE: Data Influence Cascade in Decentralized LearningTongtian Zhu, Wenhao Li, Can Wang, Fengxiang HeICLR 2025
Builds on8
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- A Unified Theory of Decentralized SGD with Changing Topology and Local UpdatesAnastasia Koloskova, Nicolas Loizou, Sadra Boreiri, Martin Jaggi et al.ICML 2020 · 623 citations
- Consensus Control for Decentralized Deep LearningLingjing Kong, Tao Lin, Anastasia Koloskova, Martin Jaggi et al.ICML 2021 · 100 citations
- Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component AnalysisSanjay Kariyappa, Chuan Guo, Kiwan Maeng, Wenjie Xiong et al.ICML 2023 · 43 citations
Related papers
- Muffliato: Peer-to-Peer Privacy Amplification for Decentralized Optimization and AveragingEdwige Cyffers, Mathieu Even, Aurélien Bellet, Laurent MassouliéNeurIPS 2022 · 39 citations
- On the (In)security of Peer-to-Peer Decentralized Machine LearningDario Pasquini, Mathilde Raynal, Carmela TroncosoS&P 2023
- GRAIN: Exact Graph Reconstruction from GradientsMaria Drencheva, Ivo Petrov, Maximilian Baader, Dimitar Iliev Dimitrov et al.ICLR 2025
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang et al.CVPR 2021
- Loki: Large-scale Data Reconstruction Attack against Federated Learning through Model ManipulationJoshua C. Zhao, Atul Sharma, Ahmed Roushdy Elkordy, Yahya H. Ezzeldin et al.S&P 2024 · 64 citations
