arXiv · 2212.03714
Reconstructing Training Data from Model Gradient, Provably
Abstract
Understanding when and how much a model gradient leaks information about the training sample is an important question in privacy. In this paper, we present a surprising result: even without training or memorizing the data, we can fully reconstruct the training samples from a single gradient query at a randomly chosen parameter value. We prove the identifiability of the training data under mild conditions: with shallow or deep neural networks and a wide range of activation functions. We also present a statistically and computationally efficient algorithm based on tensor decomposition to reconstruct the training data. As a provable attack that reveals sensitive training data, our findings suggest potential severe threats to privacy, especially in federated learning.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Zihan Wang, Jason D. Lee, Qi Lei. 2022-12-07. Reconstructing Training Data from Model Gradient, Provably. https://arxiv.org/abs/2212.03714
Cite the original work for its findings. Save a collection to share your selection of sources.