Life sciences · Preprint
arXiv · September 9, 2026
Raises a question worth testing. It does not answer one.
This preprint introduces a novel gradient inversion attack inspired by erasure-correcting codes that recovers training data batches from federated learning updates at scales and accuracy previously thought limited by theory. The work is a theoretical and computational contribution demonstrating that privacy risks in federated learning have been underestimated; it does not evaluate defenses, real-world deployment scenarios, or clinical applicability.
Algorithmic attack development and benchmarking study. Intervention: Cascading gradient inversion attack via LT-Code inspired peeling algorithm.. Compared with: Prior single-round analytic reconstruction attacks..
Prior single-round attacks recover only about half of a batch of size 100 even with full network control; proposed attacks exceed known theoretical upper bounds. Proposed attacks recover batches exactly with every sample's label from a single FedSGD round on eight image and tabular benchmarks. Passive attacker observing honestly trained network recovers 94–100% of ImageNet batches at sizes up to 128.
Safety was not reported in the material analysed. Check the source before drawing any conclusion about harm.
The source did not state who this applies to in practice.
A novel computational attack on federated learning that demonstrates theoretical vulnerability through algorithmic construction and benchmarking, but does not address clinical, patient, or real-world deployment outcomes.
As stated by the source record.
Quoted from the source exactly as published.
Graded across the dimensions that decide whether you should act, each from what the source actually supports. There is no single score, and where a dimension was not assessed it says so.
Federated learning shares model updates rather than raw data, yet these updates can be inverted to reconstruct the clients' training data. Analytic reconstruction attacks, which invert a gradient in closed form, degrade as the batch grows: prior single-round attacks recover only about half of a batch of size $100$ even when the attacker fully controls the network parameters, and known upper bounds limit what any such method can recover. We establish a connection between gradient inversion and the theory of erasure-correcting codes, and use it to construct attacks that exceed these bounds. Our attacks recover batches exactly, together with every sample's label, from a single FedSGD round, and certify each recovery without ground-truth data. On eight image and tabular benchmarks they outperform prior single-round attacks by a wide margin. Even a passive attacker who only observes an honestly trained network recovers $94$--$100\%$ of ImageNet batches at sizes up to $128$, more than prior single-round attacks achieve even with active manipulation of the model, and in the active setting more than $90\%$ is recovered at batch sizes of several hundred. These results show that the privacy leakage of federated learning has been underestimated.
Taken from the source record, never inferred. Follow any of these and new work involving them reaches your briefing.