arXiv Machine Learning

Trajectory-Aware Information Matching for Multi-Step Gradient Inversion in Federated Learning

arXiv:2509. 22082v3 Announce Type: replace Abstract: Federated learning enables distributed information sharing and collaborative model training without exposing raw client data.

arXiv Machine Learning
Jun 2

Profiling Privacy Preservation Against Gradient Inversion Attacks in Tabular Federated Learning

arXiv:2606. 00986v1 Announce Type: new Abstract: Federated learning (FL) enables multiple data holders to train machine learning models collaboratively without centralizing raw data, making it useful in privacy sensitive domains such as healthcare and institutional data sharing.

By Ivo Osterberg Nilsson, Maximilian Birr Engvall, Viktor Valadi, Teddy Lazebnik
arXiv AI
Sep 11

Cascading Gradient Inversion via LT-Code Inspired Peeling in Federated Learning

The paper introduces a new gradient inversion attack for federated learning that leverages concepts from erasure‑correcting codes to recover entire training batches and their labels from a single FedSGD round. Unlike previous analytic attacks, this method can exactly reconstruct batches of up to 128 samples on ImageNet and achieves over 90% recovery even when the attacker actively manipulates the model. The study demonstrates that federated learning’s privacy leakage is far greater than previously estimated.

By Saeed Shariati, Mohsen Alambardar Meybodi
arXiv Machine Learning
Sep 25

Temporal Gradient Inversion for Private Trajectory Reconstruction in Embodied Reinforcement Learning

The paper introduces TRACE, an amortized temporal gradient‑inversion attack that reconstructs private observation‑action trajectories from per‑step policy gradients in embodied reinforcement‑learning agents. TRACE exploits cross‑time correlation between gradients and exact action recovery from policy‑head gradients, achieving high reconstruction quality (18.8 dB PSNR) and near‑perfect action recovery with minimal computation. The study demonstrates TRACE’s effectiveness across various neural architectures and input modalities, and suggests that protecting temporal gradient streams may require sequence‑aware privacy mechanisms.

By Sudip Bhujel, Shanghao Shi, Ruiquan Huang, Ning Zhang, Yang Xiao
Hugging Face Trending Papers
Jun 1

IntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning

Heterogeneous Differential Privacy (HDP) in Federated Learning (FL) allows clients to select individual privacy budgets ($\varepsilon_i$) according to institutional policies and data sensitivity. In practice, many HDP-FL systems employ $\varepsilon$-aware server aggregation to improve model utility by re-weighting client updates according to their declared privacy budgets.

arXiv Machine Learning
Aug 18

FedADB: Class Anchor-Driven Dual-Branch Federated Learning for Mitigating Forgetting

arXiv:2608. 15310v1 Announce Type: cross Abstract: Multimodal data collected by heterogeneous devices are used for collaborative training, where federated learning (FL) serves as a key paradigm for effective distributed modeling with data privacy preservation.

By Zhenyan Liu, Hua Zhang, Haoran Gao, Qi Li, Hongliang Zhu, Huiyu Zhou, Zongliang Shen, Yanxin Xu, Jiahui Wang
arXiv AI
3d ago

Aegis: Generative Gradient Masking for Privacy-Preserving Medical Federated Learning

Aegis is a client‑side defense for medical federated learning that protects against model inversion attacks by adding a masking gradient derived from locally synthesized data. The method exploits the fact that attacks fail when the effective batch size exceeds the model’s leakage capacity, turning this bottleneck into a privacy guarantee. Experiments on MNIST, CIFAR‑10, and MedMNIST datasets show that Aegis neutralizes state‑of‑the‑art attacks while preserving model accuracy and adding only modest overhead.

By Chaoyu Zhang, Shanghao Shi, Heng Jin, Ning Wang, Y. Thomas Hou, Wenjing Lou
arXiv Machine Learning
1d ago

Latent Information Sharing for Accelerating Federated Learning

The paper introduces a latent information sharing scheme for federated learning that mitigates client drift by sharing a small amount of hidden‑layer activations. The authors demonstrate both theoretically and empirically that this approach improves training efficiency while maintaining convergence guarantees and data privacy. Compared to existing methods such as FedProx, SCAFFOLD, FedPVR, FedProto, and SplitFed, the proposed method achieves higher model accuracy within a fixed round budget without adding significant communication overhead.

By Seungjun Lee, Ensieh Khazaei, Dimitrios Hatzinakos, Baturalp Buyukates, Sunwoo Lee