Back to results

ETH Zurich

Testing Federated Learning Privacy Through Gradient Leakage Attacks

Abstract

dc:description

Federated Learning (FL) has recently gained popularity as a way of collaboratively training machine learning models across multiple clients. FL training proceeds in communication rounds, in which each client receives a global model from the FL server and sends back parameter updates computed on its local data using stochastic gradient descent. When all client updates are received, the server aggregates them, resulting in a new global model that is then used in the next communication round. FL has recently seen a widespread use in domains where protecting sensitive data is essential, as the raw client data is never directly transmitted. Despite its popularity, however, the exact privacy protections afforded by FL are not well understood. Specifically, the existence of the recently discovered gradient leakage attacks demonstrates that private client data can sometimes be recovered from the parameter updates shared with the FL server. Prior to this research, most gradient leakage attacks were severely limited in scope, underestimating their practical impact. The goal of this thesis, therefore, is to largely expand the applicability of gradient leakage attacks across different dimensions, demonstrating that they pose realistic threat and establishing a much more precise upper bound on the FL protection capabilities. Specifically, this thesis introduces three new attacks in the realistic but challenging "honest-but-curious" setting where the attacker cannot modify the FL protocol and, instead, only passively observes the updates — LAMP, DLFA, and SPEAR, which we outline next. Extracting Text from Gradients with Language Model Priors (LAMP) demonstrates that gradient leakage attacks are applicable beyond the traditional image domain, showing they can be effective in discrete input domains such as text. Data Leakage in Federated Averaging (DLFA), demonstrates that gradient leakage attacks are effective against more commonly-used FL protocols like Federated Averaging (FedAvg). Finally, Sparsity Exploiting Activation Recovery (SPEAR) theoretically analyzes the gradients of linear layers with ReLU activations to show that the special structure of these commonly used layers allows for exact reconstruction of batched client data, simultaneously theoretically justifying the success of prior optimization-based attacks and significantly improving their results on some commonly-used networks. Together, these attacks represent a significant step towards assessing the true vulnerability of FL to privacy attacks.

Degree

thesis:*
Grantor dc:publisher
ETH Zurich
Year dc:date
2025

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Dimitrov, Dimitar Iliev
Contributors dc:contributor
  • Vechev, Martin
  • Geiping, Jonas
  • Konstantinov, Nikola
  • Blaschko, Matthew B.

Subjects

dc:subject × 3

Rights

dc:rights
Statement dc:rights
  • info:eu-repo/semantics/openAccess
  • Creative Commons Attribution-ShareAlike 4.0 International
Language dc:language
en

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:www.research-collection.ethz.ch:20.500.11850/739149

Chain of custody

source
Harvested from
ETH Zürich
Base URL
www.research-collection.ethz.ch/oai/request
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
citation

Dimitrov, Dimitar Iliev. Testing Federated Learning Privacy Through Gradient Leakage Attacks. ETH Zurich, 2025. http://hdl.handle.net/20.500.11850/739149