{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:00:30Z","timestamp":1783008030424,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":55,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690292","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"3525-3539","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Uncovering Gradient Inversion Risks in Practical Language Model Training"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2307-2771","authenticated-orcid":false,"given":"Xinguo","family":"Feng","sequence":"first","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2392-3751","authenticated-orcid":false,"given":"Zhongkui","family":"Ma","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6536-2948","authenticated-orcid":false,"given":"Zihan","family":"Wang","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-1704-5374","authenticated-orcid":false,"given":"Eu Joe","family":"Chegne","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5550-5845","authenticated-orcid":false,"given":"Mengyao","family":"Ma","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9695-7947","authenticated-orcid":false,"given":"Alsharif","family":"Abuadbba","sequence":"additional","affiliation":[{"name":"CSIRO's Data61, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6390-9890","authenticated-orcid":false,"given":"Guangdong","family":"Bai","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","volume-title":"Diogo Almeida, Janko Altenschmidt, Sam Altman, Shyamal Anadkat, et al.","author":"Achiam Josh","year":"2023","unstructured":"Josh Achiam, Steven Adler, Sandhini Agarwal, Lama Ahmad, Ilge Akkaya, Florencia Leoni Aleman, Diogo Almeida, Janko Altenschmidt, Sam Altman, Shyamal Anadkat, et al. 2023. GPT-4 technical report. arXiv preprint arXiv:2303.08774 (2023)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Yoshinori Aono Takuya Hayashi Lihua Wang Shiho Moriai et al. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE transactions on information forensics and security Vol. 13 5 (2017) 1333--1345.","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"e_1_3_2_1_4_1","volume-title":"Lamp: Extracting text from gradients with language model priors. In the 2022 Advances in Neural Information Processing Systems (NeurIPS). 7641--7654.","author":"Balunovic Mislav","year":"2022","unstructured":"Mislav Balunovic, Dimitar Dimitrov, Nikola Jovanovi\u0107, and Martin Vechev. 2022. Lamp: Extracting text from gradients with language model priors. In the 2022 Advances in Neural Information Processing Systems (NeurIPS). 7641--7654."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3570361.3613277"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the 2021 USENIX Security Symposium (USENIX Security). 2633--2650","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al. 2021. Extracting training data from large language models. In Proceedings of the 2021 USENIX Security Symposium (USENIX Security). 2633--2650."},{"key":"e_1_3_2_1_8_1","volume-title":"Tag: Gradient attack on transformer-based language models. arXiv preprint arXiv:2103.06819","author":"Deng Jieren","year":"2021","unstructured":"Jieren Deng, Yijue Wang, Ji Li, Chao Shang, Hang Liu, Sanguthevar Rajasekaran, and Caiwen Ding. 2021. Tag: Gradient attack on transformer-based language models. arXiv preprint arXiv:2103.06819 (2021)."},{"key":"e_1_3_2_1_9_1","volume-title":"Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018)."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of the 2021 International Conference on Learning Representations (ICLR).","author":"Dosovitskiy Alexey","year":"2021","unstructured":"Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, Jakob Uszkoreit, and Neil Houlsby. 2021. An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. In Proceedings of the 2021 International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_11_1","unstructured":"FedML. 2023. Releasing FedLLM: Build Your Own Large Language Models on Proprietary Data using the FedML Platform. https:\/\/blog.fedml.ai\/releasing-fedllm-build-your-own-large-language-models-on-proprietary-data-using-the-fedml-platform\/. Accessed: January 2024."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 2022 International Conference on Learning Representations (ICLR).","author":"Fowl Liam","year":"2022","unstructured":"Liam Fowl, Jonas Geiping, Steven Reich, Yuxin Wen, Wojtek Czaja, Micah Goldblum, and Tom Goldstein. 2022. Decepticons: Corrupted transformers breach privacy in federated learning for language models. In Proceedings of the 2022 International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_13_1","unstructured":"Jonas Geiping Hartmut Bauermeister Hannah Dr\u00f6ge and Michael Moeller. 2020. Inverting gradients-how easy is it to break privacy in federated learning?. In the 2020 Advances in Neural Information Processing Systems (NeurIPS). 16937--16947."},{"key":"e_1_3_2_1_14_1","volume-title":"breaching. https:\/\/github.com\/JonasGeiping\/breaching","author":"Geiping Jonas","year":"2023","unstructured":"Jonas Geiping, Liam Fowl, and Yuxin Wen. 2023. breaching. https:\/\/github.com\/JonasGeiping\/breaching. Assessed: August 2023."},{"key":"e_1_3_2_1_15_1","unstructured":"Samyak Gupta Yangsibo Huang Zexuan Zhong Tianyu Gao Kai Li and Danqi Chen. 2022. Recovering private text in federated learning of language models. In the 2022 Advances in Neural Information Processing Systems (NeurIPS). 8130--8143."},{"key":"e_1_3_2_1_16_1","volume-title":"Improving neural networks by preventing co-adaptation of feature detectors. arXiv preprint arXiv:1207.0580","author":"Hinton Geoffrey E","year":"2012","unstructured":"Geoffrey E Hinton, Nitish Srivastava, Alex Krizhevsky, Ilya Sutskever, and Ruslan R Salakhutdinov. 2012. Improving neural networks by preventing co-adaptation of feature detectors. arXiv preprint arXiv:1207.0580 (2012)."},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the 2020 International Conference on Learning Representations (ICLR).","author":"Holtzman Ari","year":"2020","unstructured":"Ari Holtzman, Jan Buys, Li Du, Maxwell Forbes, and Yejin Choi. 2020. The curious case of neural text degeneration. In Proceedings of the 2020 International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_18_1","unstructured":"Pingyi Hu Zihan Wang Ruoxi Sun Hu Wang and Minhui Xue. 2022. M ^4 I: Multi-modal Models Membership Inference. In the 2022 Advances in Neural Information Processing Systems (NeurIPS). 1867--1882."},{"key":"e_1_3_2_1_19_1","unstructured":"Yangsibo Huang Samyak Gupta Zhao Song Kai Li and Sanjeev Arora. 2021. Evaluating gradient inversion attacks and defenses in federated learning. In the 2021 Advances in Neural Information Processing Systems (NeurIPS). 7232--7241."},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of the 2020 International Conference on Machine Learning (ICML). 4507--4518","author":"Huang Yangsibo","year":"2020","unstructured":"Yangsibo Huang, Zhao Song, Kai Li, and Sanjeev Arora. 2020. Instahide: Instance-hiding schemes for private distributed learning. In Proceedings of the 2020 International Conference on Machine Learning (ICML). 4507--4518."},{"key":"e_1_3_2_1_21_1","volume-title":"Accessed","year":"2022","unstructured":"Huggingface. 2022. Tweet Sentiment Extraction. https:\/\/huggingface.co\/datasets\/SetFit\/tweet_sentiment_extraction. Accessed: January, 2024."},{"key":"e_1_3_2_1_22_1","volume-title":"Accessed","year":"2024","unstructured":"Huggingface. 2024. Yahoo Answers Topics. https:\/\/huggingface.co\/datasets\/community-datasets\/yahoo_answers_topics. Accessed: January, 2024."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1121\/1.2016299"},{"key":"e_1_3_2_1_24_1","unstructured":"Jinwoo Jeon Kangwook Lee Sewoong Oh Jungseul Ok et al. 2021. Gradient inversion with generative image prior. In the 2021 Advances in Neural Information Processing Systems (NeurIPS). 29898--29908."},{"key":"e_1_3_2_1_25_1","volume-title":"Tinybert: Distilling bert for natural language understanding. arXiv preprint arXiv:1909.10351","author":"Jiao Xiaoqi","year":"2019","unstructured":"Xiaoqi Jiao, Yichun Yin, Lifeng Shang, Xin Jiang, Xiao Chen, Linlin Li, Fang Wang, and Qun Liu. 2019. Tinybert: Distilling bert for natural language understanding. arXiv preprint arXiv:1909.10351 (2019)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.2981314"},{"key":"e_1_3_2_1_27_1","volume-title":"ROUGE: A Package for Automatic Evaluation of Summaries. In Text Summarization Branches Out. 74--81.","author":"Lin Chin-Yew","year":"2004","unstructured":"Chin-Yew Lin. 2004. ROUGE: A Package for Automatic Evaluation of Summaries. In Text Summarization Branches Out. 74--81."},{"key":"e_1_3_2_1_28_1","volume-title":"Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692","author":"Liu Yinhan","year":"2019","unstructured":"Yinhan Liu, Myle Ott, Naman Goyal, Jingfei Du, Mandar Joshi, Danqi Chen, Omer Levy, Mike Lewis, Luke Zettlemoyer, and Veselin Stoyanov. 2019. Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692 (2019)."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the 2019 International Conference on Learning Representations (ICLR).","author":"Loshchilov Ilya","year":"2019","unstructured":"Ilya Loshchilov and Frank Hutter. 2019. Decoupled weight decay regularization. In Proceedings of the 2019 International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00981"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3590334"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/0005-2795(75)90109-9"},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of the 2017 International Conference on Artificial Intelligence and Statistics (AISTATS). 1273--1282","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 2017 International Conference on Artificial Intelligence and Statistics (AISTATS). 1273--1282."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.asej.2014.04.011"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.570"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.5120\/17870-8810"},{"key":"e_1_3_2_1_38_1","unstructured":"Long Ouyang Jeffrey Wu Xu Jiang Diogo Almeida Carroll Wainwright Pamela Mishkin Chong Zhang Sandhini Agarwal Katarina Slama Alex Ray et al. 2022. Training language models to follow instructions with human feedback. In the 2022 Advances in Neural Information Processing Systems (NeurIPS). 27730--27744."},{"key":"e_1_3_2_1_39_1","volume-title":"Seeing stars: Exploiting class relationships for sentiment categorization with respect to rating scales. arXiv preprint cs\/0506075","author":"Pang Bo","year":"2005","unstructured":"Bo Pang and Lillian Lee. 2005. Seeing stars: Exploiting class relationships for sentiment categorization with respect to rating scales. arXiv preprint cs\/0506075 (2005)."},{"key":"e_1_3_2_1_40_1","unstructured":"Alec Radford Jeffrey Wu Rewon Child David Luan Dario Amodei Ilya Sutskever et al. 2019. Language models are unsupervised multitask learners. OpenAI blog Vol. 1 8 (2019) 9."},{"key":"e_1_3_2_1_41_1","volume-title":"TensorFlow code and pre-trained models for BERT. https:\/\/github.com\/google-research\/bert","author":"Research Google","year":"2024","unstructured":"Google Research. 2020. TensorFlow code and pre-trained models for BERT. https:\/\/github.com\/google-research\/bert. Accessed: January 2024."},{"key":"e_1_3_2_1_42_1","volume-title":"Artificial intelligence a modern approach. Pearson Education","author":"Russell Stuart J","unstructured":"Stuart J Russell. 2010. Artificial intelligence a modern approach. Pearson Education, Inc."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i8.26163"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510033"},{"key":"e_1_3_2_1_47_1","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. In the 2017 Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00290"},{"key":"e_1_3_2_1_49_1","volume-title":"Stacey Truex, and Yanzhao Wu.","author":"Wei Wenqi","year":"2020","unstructured":"Wenqi Wei, Ling Liu, Margaret Loper, Ka-Ho Chow, Mehmet Emre Gursoy, Stacey Truex, and Yanzhao Wu. 2020. A framework for evaluating gradient leakage attacks in federated learning. arXiv preprint arXiv:2004.10397 (2020)."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"e_1_3_2_1_52_1","volume-title":"roberta-tiny-cased. https:\/\/github.com\/haisongzhang\/roberta-tiny-cased","author":"Zhang Haisong","year":"2024","unstructured":"Haisong Zhang. 2020. roberta-tiny-cased. https:\/\/github.com\/haisongzhang\/roberta-tiny-cased. Accessed: January 2024."},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the 2018 International Conference on Learning Representations (ICLR).","author":"Zhang Hongyi","year":"2018","unstructured":"Hongyi Zhang, Moustapha Cisse, Yann N Dauphin, and David Lopez-Paz. 2018. mixup: Beyond empirical risk minimization. In Proceedings of the 2018 International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_54_1","volume-title":"Konda Reddy Mopuri, and Hakan Bilen","author":"Zhao Bo","year":"2020","unstructured":"Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. 2020. idlg: Improved deep leakage from gradients. arXiv preprint arXiv:2001.02610 (2020)."},{"key":"e_1_3_2_1_55_1","unstructured":"Ligeng Zhu Zhijian Liu and Song Han. 2019. Deep leakage from gradients. In the 2019 Advances in Neural Information Processing Systems (NeurIPS)."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690292","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690292","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T05:57:52Z","timestamp":1755842272000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690292"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":55,"alternative-id":["10.1145\/3658644.3690292","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690292","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}