Harmful Bias: A General Label-Leakage Attack on Federated Learning from Bias Gradients
Nadav Gat, Mahmood Sharif · 2024
Federated learning (FL) enables several users to train machine-learning models jointly without explicitly sharing data with one another. This regime is particularly helpful in cases where keeping the data private and secure is essential (e.g., medical records). However, recent work has shown that FL does not guarantee privacy--in classification tasks, the training-data labels, and even the inputs, may be reconstructed from information users share during training.