{"id":{"repo_id":"ethz","oai_identifier":"oai:www.research-collection.ethz.ch:20.500.11850/739149"},"canonical_url":"https://search.dev.ndltd.org/etd/ethz/oai:www.research-collection.ethz.ch:20.500.11850/739149","repository":{"repo_id":"ethz","name":"ETH Zürich","base_url":"https://www.research-collection.ethz.ch/oai/request"},"display":{"title":"Testing Federated Learning Privacy Through Gradient Leakage Attacks","abstract":"Federated Learning (FL) has recently gained popularity as a way of collaboratively training machine learning models across multiple clients. FL training proceeds in communication rounds, in which each client receives a global model from the FL server and sends back parameter updates computed on its local data using stochastic gradient descent. When all client updates are received, the server aggregates them, resulting in a new global model that is then used in the next communication round. FL has recently seen a widespread use in domains where protecting sensitive data is essential, as the raw client data is never directly transmitted. Despite its popularity, however, the exact privacy protections afforded by FL are not well understood. Specifically, the existence of the recently discovered gradient leakage attacks demonstrates that private client data can sometimes be recovered from the parameter updates shared with the FL server. Prior to this research, most gradient leakage attacks were severely limited in scope, underestimating their practical impact. The goal of this thesis, therefore, is to largely expand the applicability of gradient leakage attacks across different dimensions, demonstrating that they pose realistic threat and establishing a much more precise upper bound on the FL protection capabilities. Specifically, this thesis introduces three new attacks in the realistic but challenging \"honest-but-curious\" setting where the attacker cannot modify the FL protocol and, instead, only passively observes the updates — LAMP, DLFA, and SPEAR, which we outline next. Extracting Text from Gradients with Language Model Priors (LAMP) demonstrates that gradient leakage attacks are applicable beyond the traditional image domain, showing they can be effective in discrete input domains such as text. Data Leakage in Federated Averaging (DLFA), demonstrates that gradient leakage attacks are effective against more commonly-used FL protocols like Federated Averaging (FedAvg). Finally, Sparsity Exploiting Activation Recovery (SPEAR) theoretically analyzes the gradients of linear layers with ReLU activations to show that the special structure of these commonly used layers allows for exact reconstruction of batched client data, simultaneously theoretically justifying the success of prior optimization-based attacks and significantly improving their results on some commonly-used networks. Together, these attacks represent a significant step towards assessing the true vulnerability of FL to privacy attacks.","abstract_html":"Federated Learning (FL) has recently gained popularity as a way of collaboratively training machine learning models across multiple clients. FL training proceeds in communication rounds, in which each client receives a global model from the FL server and sends back parameter updates computed on its local data using stochastic gradient descent. When all client updates are received, the server aggregates them, resulting in a new global model that is then used in the next communication round. FL has recently seen a widespread use in domains where protecting sensitive data is essential, as the raw client data is never directly transmitted. Despite its popularity, however, the exact privacy protections afforded by FL are not well understood. Specifically, the existence of the recently discovered gradient leakage attacks demonstrates that private client data can sometimes be recovered from the parameter updates shared with the FL server. Prior to this research, most gradient leakage attacks were severely limited in scope, underestimating their practical impact. The goal of this thesis, therefore, is to largely expand the applicability of gradient leakage attacks across different dimensions, demonstrating that they pose realistic threat and establishing a much more precise upper bound on the FL protection capabilities. Specifically, this thesis introduces three new attacks in the realistic but challenging &quot;honest-but-curious&quot; setting where the attacker cannot modify the FL protocol and, instead, only passively observes the updates — LAMP, DLFA, and SPEAR, which we outline next. Extracting Text from Gradients with Language Model Priors (LAMP) demonstrates that gradient leakage attacks are applicable beyond the traditional image domain, showing they can be effective in discrete input domains such as text. Data Leakage in Federated Averaging (DLFA), demonstrates that gradient leakage attacks are effective against more commonly-used FL protocols like Federated Averaging (FedAvg). Finally, Sparsity Exploiting Activation Recovery (SPEAR) theoretically analyzes the gradients of linear layers with ReLU activations to show that the special structure of these commonly used layers allows for exact reconstruction of batched client data, simultaneously theoretically justifying the success of prior optimization-based attacks and significantly improving their results on some commonly-used networks. Together, these attacks represent a significant step towards assessing the true vulnerability of FL to privacy attacks.","abstract_has_math":false,"creators":["Dimitrov, Dimitar Iliev"],"institution":"ETH Zurich","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Vechev, Martin","Geiping, Jonas","Konstantinov, Nikola","Blaschko, Matthew B."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025","date_published":"2025","updated_at":"2026-07-27T19:28:46Z","subjects":["Gradient leakage; Federated Learning; Privacy; Machine Learning; Privacy attacks","info:eu-repo/classification/ddc/004","Data processing, computer science"],"languages":["en"],"rights":["info:eu-repo/semantics/openAccess","Creative Commons Attribution-ShareAlike 4.0 International"],"rights_urls":["http://creativecommons.org/licenses/by-sa/4.0/"],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["https://doi.org/10.3929/ethz-b-000739149"],"render_values":[{"text":"https://doi.org/10.3929/ethz-b-000739149","href":"https://doi.org/10.3929/ethz-b-000739149","code":true}]}]},"links":{"outbound_url":"http://hdl.handle.net/20.500.11850/739149","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Vechev, Martin","Geiping, Jonas","Konstantinov, Nikola","Blaschko, Matthew B."]},{"key":"dc:creator","label":"Author","values":["Dimitrov, Dimitar Iliev"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025"]},{"key":"dc:publisher","label":"Institution","values":["ETH Zurich"]},{"key":"dc:type","label":"Dc Type","values":["info:eu-repo/semantics/doctoralThesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Gradient leakage; Federated Learning; Privacy; Machine Learning; Privacy attacks","info:eu-repo/classification/ddc/004","Data processing, computer science"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["info:eu-repo/semantics/openAccess","http://creativecommons.org/licenses/by-sa/4.0/","Creative Commons Attribution-ShareAlike 4.0 International"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/20.500.11850/739149","https://doi.org/10.3929/ethz-b-000739149"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Federated Learning (FL) has recently gained popularity as a way of collaboratively training machine learning models across multiple clients. FL training proceeds in communication rounds, in which each client receives a global model from the FL server and sends back parameter updates computed on its local data using stochastic gradient descent. When all client updates are received, the server aggregates them, resulting in a new global model that is then used in the next communication round. FL has recently seen a widespread use in domains where protecting sensitive data is essential, as the raw client data is never directly transmitted. Despite its popularity, however, the exact privacy protections afforded by FL are not well understood. Specifically, the existence of the recently discovered gradient leakage attacks demonstrates that private client data can sometimes be recovered from the parameter updates shared with the FL server. Prior to this research, most gradient leakage attacks were severely limited in scope, underestimating their practical impact. The goal of this thesis, therefore, is to largely expand the applicability of gradient leakage attacks across different dimensions, demonstrating that they pose realistic threat and establishing a much more precise upper bound on the FL protection capabilities. Specifically, this thesis introduces three new attacks in the realistic but challenging \"honest-but-curious\" setting where the attacker cannot modify the FL protocol and, instead, only passively observes the updates — LAMP, DLFA, and SPEAR, which we outline next. Extracting Text from Gradients with Language Model Priors (LAMP) demonstrates that gradient leakage attacks are applicable beyond the traditional image domain, showing they can be effective in discrete input domains such as text. Data Leakage in Federated Averaging (DLFA), demonstrates that gradient leakage attacks are effective against more commonly-used FL protocols like Federated Averaging (FedAvg). Finally, Sparsity Exploiting Activation Recovery (SPEAR) theoretically analyzes the gradients of linear layers with ReLU activations to show that the special structure of these commonly used layers allows for exact reconstruction of batched client data, simultaneously theoretically justifying the success of prior optimization-based attacks and significantly improving their results on some commonly-used networks. Together, these attacks represent a significant step towards assessing the true vulnerability of FL to privacy attacks."]},{"key":"dc:format","label":"Dc Format","values":["application/application/pdf"]},{"key":"dc:title","label":"Title","values":["Testing Federated Learning Privacy Through Gradient Leakage Attacks"]}]}],"canonical_facts":{"dc:contributor":["Vechev, Martin","Geiping, Jonas","Konstantinov, Nikola","Blaschko, Matthew B."],"dc:creator":["Dimitrov, Dimitar Iliev"],"dc:date":["2025"],"dc:description":["Federated Learning (FL) has recently gained popularity as a way of collaboratively training machine learning models across multiple clients. FL training proceeds in communication rounds, in which each client receives a global model from the FL server and sends back parameter updates computed on its local data using stochastic gradient descent. When all client updates are received, the server aggregates them, resulting in a new global model that is then used in the next communication round. FL has recently seen a widespread use in domains where protecting sensitive data is essential, as the raw client data is never directly transmitted. Despite its popularity, however, the exact privacy protections afforded by FL are not well understood. Specifically, the existence of the recently discovered gradient leakage attacks demonstrates that private client data can sometimes be recovered from the parameter updates shared with the FL server. Prior to this research, most gradient leakage attacks were severely limited in scope, underestimating their practical impact. The goal of this thesis, therefore, is to largely expand the applicability of gradient leakage attacks across different dimensions, demonstrating that they pose realistic threat and establishing a much more precise upper bound on the FL protection capabilities. Specifically, this thesis introduces three new attacks in the realistic but challenging \"honest-but-curious\" setting where the attacker cannot modify the FL protocol and, instead, only passively observes the updates — LAMP, DLFA, and SPEAR, which we outline next. Extracting Text from Gradients with Language Model Priors (LAMP) demonstrates that gradient leakage attacks are applicable beyond the traditional image domain, showing they can be effective in discrete input domains such as text. Data Leakage in Federated Averaging (DLFA), demonstrates that gradient leakage attacks are effective against more commonly-used FL protocols like Federated Averaging (FedAvg). Finally, Sparsity Exploiting Activation Recovery (SPEAR) theoretically analyzes the gradients of linear layers with ReLU activations to show that the special structure of these commonly used layers allows for exact reconstruction of batched client data, simultaneously theoretically justifying the success of prior optimization-based attacks and significantly improving their results on some commonly-used networks. Together, these attacks represent a significant step towards assessing the true vulnerability of FL to privacy attacks."],"dc:format":["application/application/pdf"],"dc:identifier":["http://hdl.handle.net/20.500.11850/739149","https://doi.org/10.3929/ethz-b-000739149"],"dc:language":["en"],"dc:publisher":["ETH Zurich"],"dc:rights":["info:eu-repo/semantics/openAccess","http://creativecommons.org/licenses/by-sa/4.0/","Creative Commons Attribution-ShareAlike 4.0 International"],"dc:subject":["Gradient leakage; Federated Learning; Privacy; Machine Learning; Privacy attacks","info:eu-repo/classification/ddc/004","Data processing, computer science"],"dc:title":["Testing Federated Learning Privacy Through Gradient Leakage Attacks"],"dc:type":["info:eu-repo/semantics/doctoralThesis"]},"updated_at":"2026-07-27T19:28:46Z"}