Timezone: »
Distributed learning paradigms such as federated learning often involve transmission of model updates, or gradients, over a network, thereby avoiding transmission of private data. However, it is possible for sensitive information about the training data to be revealed from such gradients. Prior works have demonstrated that labels can be revealed analytically from the last layer of certain models (e.g., ResNet), or they can be reconstructed jointly with model inputs by using Gradients Matching [Zhu et al.] with additional knowledge about the current state of the model. In this work, we propose a method to discover the set of labels of training samples from only the gradient of the last layer and the id to label mapping. Our method is applicable to a wide variety of model architectures across multiple domains. We demonstrate the effectiveness of our method for model training in two domains - image classification, and automatic speech recognition. Furthermore, we show that existing reconstruction techniques improve their efficacy when used in conjunction with our method. Conversely, we demonstrate that gradient quantization and sparsification can significantly reduce the success of the attack.
Author Information
Trung Dang (Boston University)
Om Thakkar (Google)
Swaroop Ramaswamy (Google)
Rajiv Mathews (Google)
Peter Chin (Boston University & BBN Technologies)
Françoise Beaufays
More from the Same Authors
-
2020 : Understanding Unintended Memorization in Federated Learning »
Om Thakkar -
2021 : Jointly Learning from Decentralized (Federated) and Centralized Data to Mitigate Distribution Shift »
Sean Augenstein · Andrew S Hard · Rajiv Mathews -
2021 Poster: Differentially Private Learning with Adaptive Clipping »
Galen Andrew · Om Thakkar · Brendan McMahan · Swaroop Ramaswamy -
2020 : Contributed Talk #7: Training Production Language Models without Memorizing User Data »
Swaroop Ramaswamy · Om Thakkar -
2020 Poster: Privacy Amplification via Random Check-Ins »
Borja Balle · Peter Kairouz · Brendan McMahan · Om Thakkar · Abhradeep Guha Thakurta -
2018 Poster: Model-Agnostic Private Learning »
Raef Bassily · Abhradeep Guha Thakurta · Om Thakkar -
2018 Oral: Model-Agnostic Private Learning »
Raef Bassily · Abhradeep Guha Thakurta · Om Thakkar -
2018 Poster: Learning to Repair Software Vulnerabilities with Generative Adversarial Networks »
Jacob Harer · Onur Ozdemir · Tomo Lazovich · Christopher Reale · Rebecca Russell · Louis Kim · Peter Chin -
2017 : Poster Session 1 and Lunch »
Sumanth Dathathri · Akshay Rangamani · Prakhar Sharma · Aruni RoyChowdhury · Madhu Advani · William Guss · Chulhee Yun · Corentin Hardy · Michele Alberti · Devendra Sachan · Andreas Veit · Takashi Shinozaki · Peter Chin