DAGER: Exact Gradient Inversion for Large Language Models
Ivo Petrov, Dimitar I. Dimitrov, Maximilian Baader, Mark Niklas Müller, Martin T. Vechev
Abstract
Federated learning works by aggregating locally computed gradients from multiple clients, thus enabling collaborative training without sharing private client data. However, prior work has shown that the data can actually be recovered by the server using so-called gradient inversion attacks. While these attacks perform well when applied on images, they are limited in the text domain and only permit approximate reconstruction of small batches and short input sequences. In this work, we propose DAGER, the first algorithm to recover whole batches of input text exactly. DAGER leverages the low-rank structure of self-attention layer gradients and the discrete nature of token embeddings to efficiently check if a given token sequence is part of the client data. We use this check to exactly recover full batches in the honest-but-curious setting without any prior on the data for both encoder- and decoder-based architectures using exhaustive heuristic search and a greedy approach, respectively. We provide an efficient GPU implementation of DAGER and show experimentally that it recovers full batches of size up to 128 on large language models (LLMs), beating prior attacks in speed (20x at same batch size), scalability (10x larger batches), and reconstruction quality (ROUGE-1/2>0.99).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- SHE-LoRA: Selective Homomorphic Encryption for Federated Tuning with Heterogeneous LoRAJianmin Liu, Li Yan, Borui Li, Lei Yu et al.ICLR 2026 · 5 citations
- Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual ApproachGuilin Deng, Silong Chen, Yuchuan Luo, Yi Liu et al.S&P 2026 · 4 citations
- Reconstructing Training Data from Adapter-based Federated Large Language ModelsSilong Chen, Yuchuan Luo, Guilin Deng, Yi Liu et al.WWW 2026
- When the Aggregator Cheats: Data-Free Backdoors in Federated LLM-based QA SystemsChenqing Zhu, Yanbo Dai, Yulong Tian, Qingming Li et al.USENIX Security 2026
- GRAIN: Exact Graph Reconstruction from GradientsMaria Drencheva, Ivo Petrov, Maximilian Baader, Dimitar Iliev Dimitrov et al.ICLR 2025
Builds on13
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified ModelsLiam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum et al.ICLR 2022 · 181 citations
- R-GAP: Recursive Gradient Attack on PrivacyJunyi Zhu, Matthew B. BlaschkoICLR 2021 · 157 citations
- Recovering Private Text in Federated Learning of Language ModelsSamyak Gupta, Yangsibo Huang, Zexuan Zhong, Tianyu Gao et al.NeurIPS 2022 · 120 citations
Related papers
- SPEAR: Exact Gradient Inversion of Batches in Federated LearningDimitar I. Dimitrov, Maximilian Baader, Mark Niklas Müller, Martin T. VechevNeurIPS 2024 · 29 citations
- LAMP: Extracting Text from Gradients with Language Model PriorsMislav Balunovic, Dimitar I. Dimitrov, Nikola Jovanovic, Martin T. VechevNeurIPS 2022 · 100 citations
- Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language ModelsLiam H. Fowl, Jonas Geiping, Steven Reich, Yuxin Wen et al.ICLR 2023 · 10 citations
- Hiding in Plain Sight: Disguising Data Stealing Attacks in Federated LearningKostadin Garov, Dimitar Iliev Dimitrov, Nikola Jovanovic, Martin T. VechevICLR 2024 · 13 citations
- Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale AggregationHong-Min Chu, Jonas Geiping, Liam H. Fowl, Micah Goldblum et al.ICLR 2023
