DAGER: Exact Gradient Inversion for Large Language Models
Ivo Petrov, Dimitar I. Dimitrov, Maximilian Baader, Mark Niklas Müller, Martin T. Vechev
摘要
Federated learning works by aggregating locally computed gradients from multiple clients, thus enabling collaborative training without sharing private client data. However, prior work has shown that the data can actually be recovered by the server using so-called gradient inversion attacks. While these attacks perform well when applied on images, they are limited in the text domain and only permit approximate reconstruction of small batches and short input sequences. In this work, we propose DAGER, the first algorithm to recover whole batches of input text exactly. DAGER leverages the low-rank structure of self-attention layer gradients and the discrete nature of token embeddings to efficiently check if a given token sequence is part of the client data. We use this check to exactly recover full batches in the honest-but-curious setting without any prior on the data for both encoder- and decoder-based architectures using exhaustive heuristic search and a greedy approach, respectively. We provide an efficient GPU implementation of DAGER and show experimentally that it recovers full batches of size up to 128 on large language models (LLMs), beating prior attacks in speed (20x at same batch size), scalability (10x larger batches), and reconstruction quality (ROUGE-1/2>0.99).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- SHE-LoRA: Selective Homomorphic Encryption for Federated Tuning with Heterogeneous LoRAJianmin Liu, Li Yan, Borui Li, Lei Yu 等ICLR 2026 · 被引用 5 次
- Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual ApproachGuilin Deng, Silong Chen, Yuchuan Luo, Yi Liu 等S&P 2026 · 被引用 4 次
- Reconstructing Training Data from Adapter-based Federated Large Language ModelsSilong Chen, Yuchuan Luo, Guilin Deng, Yi Liu 等WWW 2026
- When the Aggregator Cheats: Data-Free Backdoors in Federated LLM-based QA SystemsChenqing Zhu, Yanbo Dai, Yulong Tian, Qingming Li 等USENIX Security 2026
- GRAIN: Exact Graph Reconstruction from GradientsMaria Drencheva, Ivo Petrov, Maximilian Baader, Dimitar Iliev Dimitrov 等ICLR 2025
它引用的顶会 Paper13
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 被引用 1,822 次
- Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified ModelsLiam H. Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum 等ICLR 2022 · 被引用 181 次
- R-GAP: Recursive Gradient Attack on PrivacyJunyi Zhu, Matthew B. BlaschkoICLR 2021 · 被引用 157 次
- Recovering Private Text in Federated Learning of Language ModelsSamyak Gupta, Yangsibo Huang, Zexuan Zhong, Tianyu Gao 等NeurIPS 2022 · 被引用 120 次
相关 Paper
- SPEAR: Exact Gradient Inversion of Batches in Federated LearningDimitar I. Dimitrov, Maximilian Baader, Mark Niklas Müller, Martin T. VechevNeurIPS 2024 · 被引用 29 次
- LAMP: Extracting Text from Gradients with Language Model PriorsMislav Balunovic, Dimitar I. Dimitrov, Nikola Jovanovic, Martin T. VechevNeurIPS 2022 · 被引用 100 次
- Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language ModelsLiam H. Fowl, Jonas Geiping, Steven Reich, Yuxin Wen 等ICLR 2023 · 被引用 10 次
- Hiding in Plain Sight: Disguising Data Stealing Attacks in Federated LearningKostadin Garov, Dimitar Iliev Dimitrov, Nikola Jovanovic, Martin T. VechevICLR 2024 · 被引用 13 次
- Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale AggregationHong-Min Chu, Jonas Geiping, Liam H. Fowl, Micah Goldblum 等ICLR 2023
