the.ai

Privacy / Attacks

verified

Gradient Leakage

Federated learning sends gradients instead of data on the assumption that a gradient reveals little. It reveals a great deal: from a single update it is often possible to reconstruct the images or text that produced it, pixel by pixel, by optimising a fake input until its gradient matches. The assumption that made the design feel safe was never established.

Viz primitive · budget-splitbatch-examples = 4

batch-examples holds 50% of the budget; rest holds the remaining 50%.

Examples summed into one released gradient against the single example an attacker wants back, in examples. Drag the batch up to watch the reconstruction lose its target in the sum.

4

Reviewed by opendroid · 2026-08-18