arXiv Machine Learning
Sep 25

Temporal Gradient Inversion for Private Trajectory Reconstruction in Embodied Reinforcement Learning

The paper introduces TRACE, an amortized temporal gradient‑inversion attack that reconstructs private observation‑action trajectories from per‑step policy gradients in embodied reinforcement‑learning agents. TRACE exploits cross‑time correlation between gradients and exact action recovery from policy‑head gradients, achieving high reconstruction quality (18.8 dB PSNR) and near‑perfect action recovery with minimal computation. The study demonstrates TRACE’s effectiveness across various neural architectures and input modalities, and suggests that protecting temporal gradient streams may require sequence‑aware privacy mechanisms.

By Sudip Bhujel, Shanghao Shi, Ruiquan Huang, Ning Zhang, Yang Xiao
arXiv Machine Learning
Sep 14

PEARL: Structural Privacy-Utility Control in Human-Centric CPS via Personalized Early-Exit Deep Reinforcement Learning

PEARL is a framework for human‑centric cyber‑physical systems that uses a dual‑path Early‑Exit Deep Q‑Network to control the trade‑off between privacy and utility. By training per‑branch binary labels—Utility Confidence Labels (UCL) and Privacy Confidence Labels (PCL)—based on mutual information between private states and observable actions, PEARL selects the shallowest exit that satisfies both privacy and utility constraints, avoiding noise injection. The system includes an MI‑based feedback loop to detect behavioral drift and trigger retraining, and experiments on a smart‑home HVAC system and a VR smart classroom show a 25.67% reduction in adversarial state‑inference accuracy with only a 10‑16% utility cost.

By Mojtaba Taherisadr, Salma Elmalaki
arXiv AI
Sep 11

Cascading Gradient Inversion via LT-Code Inspired Peeling in Federated Learning

The paper introduces a new gradient inversion attack for federated learning that leverages concepts from erasure‑correcting codes to recover entire training batches and their labels from a single FedSGD round. Unlike previous analytic attacks, this method can exactly reconstruct batches of up to 128 samples on ImageNet and achieves over 90% recovery even when the attacker actively manipulates the model. The study demonstrates that federated learning’s privacy leakage is far greater than previously estimated.

By Saeed Shariati, Mohsen Alambardar Meybodi