{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T16:11:27Z","timestamp":1780762287523,"version":"3.54.1"},"reference-count":41,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"2","license":[{"start":{"date-parts":[[2022,3,3]],"date-time":"2022-03-03T00:00:00Z","timestamp":1646265600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,4,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Federated learning enables multiple users to build a joint model by sharing their model updates (gradients), while their raw data remains local on their devices. In contrast to the common belief that this provides privacy benefits, we here add to the very recent results on privacy risks when sharing gradients. Specifically, we investigate Label Leakage from Gradients (LLG), a novel attack to extract the labels of the users\u2019 training data from their shared gradients. The attack exploits the direction and magnitude of gradients to determine the presence or absence of any label. LLG is simple yet effective, capable of leaking potential sensitive information represented by labels, and scales well to arbitrary batch sizes and multiple classes. We mathematically and empirically demonstrate the validity of the attack under different settings. Moreover, empirical results show that LLG successfully extracts labels with high accuracy at the early stages of model training. We also discuss different defense mechanisms against such leakage. Our findings suggest that gradient compression is a practical technique to mitigate the attack.<\/jats:p>","DOI":"10.2478\/popets-2022-0043","type":"journal-article","created":{"date-parts":[[2022,3,5]],"date-time":"2022-03-05T04:27:38Z","timestamp":1646454458000},"page":"227-244","source":"Crossref","is-referenced-by-count":48,"title":["User-Level Label Leakage from Gradients in Federated Learning"],"prefix":"10.56553","volume":"2022","author":[{"given":"Aidmar","family":"Wainakh","sequence":"first","affiliation":[{"name":"Telecooperation Lab , Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fabrizio","family":"Ventola","sequence":"additional","affiliation":[{"name":"Artificial Intelligence and Machine Learning Lab , Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Till","family":"M\u00fc\u00dfig","sequence":"additional","affiliation":[{"name":"Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jens","family":"Keim","sequence":"additional","affiliation":[{"name":"Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carlos Garcia","family":"Cordero","sequence":"additional","affiliation":[{"name":"Telecooperation Lab , Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ephraim","family":"Zimmer","sequence":"additional","affiliation":[{"name":"Telecooperation Lab , Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tim","family":"Grube","sequence":"additional","affiliation":[{"name":"Telecooperation Lab , Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kristian","family":"Kersting","sequence":"additional","affiliation":[{"name":"Artificial Intelligence and Machine Learning Lab , Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Max","family":"M\u00fchlh\u00e4user","sequence":"additional","affiliation":[{"name":"Telecooperation Lab , Technical University of Darmstadt"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"35752","published-online":{"date-parts":[[2022,3,3]]},"reference":[{"key":"2022060207215957187_j_popets-2022-0043_ref_001","doi-asserted-by":"crossref","unstructured":"[1] Mart\u00edn Abadi, H. Brendan McMahan, Andy Chu, Ilya Mironov, Li Zhang, Ian Goodfellow, and Kunal Talwar. Deep learning with differential privacy. In Proceedings of the ACM Conference on Computer and Communications Security, 2016.10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"2022060207215957187_j_popets-2022-0043_ref_002","doi-asserted-by":"crossref","unstructured":"[2] Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et al. Privacy-preserving deep learning: Revisited and enhanced. In International Conference on Applications and Techniques in Information Security, pages 100\u2013110. Springer, 2017.10.1007\/978-981-10-5421-1_9","DOI":"10.1007\/978-981-10-5421-1_9"},{"key":"2022060207215957187_j_popets-2022-0043_ref_003","doi-asserted-by":"crossref","unstructured":"[3] Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et al. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security, 13(5):1333\u20131345, 2017.10.1109\/TIFS.2017.2787987","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"2022060207215957187_j_popets-2022-0043_ref_004","doi-asserted-by":"crossref","unstructured":"[4] Jacob Benesty, Jingdong Chen, Yiteng Huang, and Israel Cohen. Pearson correlation coefficient. In Noise reduction in speech processing, pages 1\u20134. Springer, 2009.10.1007\/978-3-642-00296-0_5","DOI":"10.1007\/978-3-642-00296-0_5"},{"key":"2022060207215957187_j_popets-2022-0043_ref_005","unstructured":"[5] Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. Practical secure aggregation for federated learning on user-held data. arXiv preprint arXiv:1611.04482, 2016."},{"key":"2022060207215957187_j_popets-2022-0043_ref_006","doi-asserted-by":"crossref","unstructured":"[6] Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. Practical secure aggregation for privacy-preserving machine learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 1175\u20131191, 2017.10.1145\/3133956.3133982","DOI":"10.1145\/3133956.3133982"},{"key":"2022060207215957187_j_popets-2022-0043_ref_007","unstructured":"[7] Harald Cram\u00e9r. Mathematical methods of statistics, volume 43. Princeton university press, 1999."},{"key":"2022060207215957187_j_popets-2022-0043_ref_008","doi-asserted-by":"crossref","unstructured":"[8] Matthew F Daley, Kristin Goddard, Melissa McClung, Arthur Davidson, Gretchen Weiss, Ted Palen, Carsie Nyirenda, Richard Platt, Brooke Courtney, and Marsha E Reichman. Using a handheld device for patient data collection: a pilot for medical countermeasures surveillance. Public Health Reports, 131(1):30\u201334, 2016.","DOI":"10.1177\/003335491613100108"},{"key":"2022060207215957187_j_popets-2022-0043_ref_009","doi-asserted-by":"crossref","unstructured":"[9] Sinead Duane, Meera Tandan, Andrew W Murphy, and Akke Vellinga. Using mobile phones to collect patient data: lessons learned from the simple study. JMIR research protocols, 6(4):e61, 2017.","DOI":"10.2196\/resprot.6389"},{"key":"2022060207215957187_j_popets-2022-0043_ref_010","unstructured":"[10] David Enthoven and Zaid Al-Ars. Fidel: Reconstructing private training samples from weight updates in federated learning. arXiv preprint arXiv:2101.00159, 2021."},{"key":"2022060207215957187_j_popets-2022-0043_ref_011","doi-asserted-by":"crossref","unstructured":"[11] Mona Flores, Ittai Dayan, Holger Roth, Aoxiao Zhong, Ahmed Harouni, Amilcare Gentili, Anas Abidin, Andrew Liu, Anthony Costa, Bradford Wood, et al. Federated learning used for predicting outcomes in sars-cov-2 patients. Research Square, 2021.10.21203\/rs.3.rs-126892\/v1780545833442676","DOI":"10.21203\/rs.3.rs-126892\/v1"},{"key":"2022060207215957187_j_popets-2022-0043_ref_012","unstructured":"[12] Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. Inverting gradients - how easy is it to break privacy in federated learning? In Hugo Larochelle, Marc\u2019Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin, editors, Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6-12, 2020, virtual, 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_013","unstructured":"[13] R. C. Geyer, T. Klein, and M. Nabi. Differentially Private Federated Learning: A Client Level Perspective. ArXiv e-prints, December 2017."},{"key":"2022060207215957187_j_popets-2022-0043_ref_014","unstructured":"[14] Ian Goodfellow, Yoshua Bengio, and Aaron Courville. Deep Learning. MIT Press, 2016. http:\/\/www.deeplearningbook.org."},{"key":"2022060207215957187_j_popets-2022-0043_ref_015","doi-asserted-by":"crossref","unstructured":"[15] Meng Hao, Hongwei Li, Xizhao Luo, Guowen Xu, Haomiao Yang, and Sen Liu. Efficient and privacy-enhanced federated learning for industrial artificial intelligence. IEEE Transactions on Industrial Informatics, 16(10):6532\u20136542, 2019.10.1109\/TII.2019.2945367","DOI":"10.1109\/TII.2019.2945367"},{"key":"2022060207215957187_j_popets-2022-0043_ref_016","unstructured":"[16] Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition, pages 770\u2013778, 2016."},{"key":"2022060207215957187_j_popets-2022-0043_ref_017","doi-asserted-by":"crossref","unstructured":"[17] Arthur Jochems, Timo M Deist, Issam El Naqa, Marc Kessler, Chuck Mayo, Jackson Reeves, Shruti Jolly, Martha Matuszak, Randall Ten Haken, Johan van Soest, et al. Developing and validating a survival prediction model for nsclc patients through distributed learning across 3 countries. International Journal of Radiation Oncology* Biology* Physics, 99(2):344\u2013352, 2017.10.1016\/j.ijrobp.2017.04.021557536028871984","DOI":"10.1016\/j.ijrobp.2017.04.021"},{"key":"2022060207215957187_j_popets-2022-0043_ref_018","unstructured":"[18] Peter Kairouz, H Brendan McMahan, Brendan Avent, Aur\u00e9lien Bellet, Mehdi Bennis, Arjun Nitin Bhagoji, Keith Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, et al. Advances and open problems in federated learning. arXiv preprint arXiv:1912.04977, 2019."},{"key":"2022060207215957187_j_popets-2022-0043_ref_019","unstructured":"[19] Alex Krizhevsky, Geoffrey Hinton, et al. Learning multiple layers of features from tiny images. MIT, 2009."},{"key":"2022060207215957187_j_popets-2022-0043_ref_020","doi-asserted-by":"crossref","unstructured":"[20] Yann LeCun, L\u00e9on Bottou, Yoshua Bengio, and Patrick Haffner. Gradient-based learning applied to document recognition. Proceedings of the IEEE, 86(11):2278\u20132324, 1998.10.1109\/5.726791","DOI":"10.1109\/5.726791"},{"key":"2022060207215957187_j_popets-2022-0043_ref_021","unstructured":"[21] Oscar Li, Jiankai Sun, Weihao Gao, Hongyi Zhang, Xin Yang, Junyuan Xie, and Chong Wang. Label leakage and protection in two-party split learning. NeurIPS 2020 Workshop on Scalability, Privacy, and Security in Federated Learning (SpicyFL), 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_022","unstructured":"[22] Qinbin Li, Zeyi Wen, and Bingsheng He. Federated learning systems: Vision, hype and reality for data privacy and protection. arXiv preprint arXiv:1907.09693, 2019."},{"key":"2022060207215957187_j_popets-2022-0043_ref_023","unstructured":"[23] Yujun Lin, Song Han, Huizi Mao, Yu Wang, and William J Dally. Deep gradient compression: Reducing the communication bandwidth for distributed training. arXiv preprint arXiv:1712.01887, 2017."},{"key":"2022060207215957187_j_popets-2022-0043_ref_024","doi-asserted-by":"crossref","unstructured":"[24] Dong C Liu and Jorge Nocedal. On the limited memory bfgs method for large scale optimization. Mathematical programming, 45(1):503\u2013528, 1989.10.1007\/BF01589116","DOI":"10.1007\/BF01589116"},{"key":"2022060207215957187_j_popets-2022-0043_ref_025","doi-asserted-by":"crossref","unstructured":"[25] Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang. Deep learning face attributes in the wild. In Proceedings of the IEEE international conference on computer vision, pages 3730\u20133738, 2015.10.1109\/ICCV.2015.425","DOI":"10.1109\/ICCV.2015.425"},{"key":"2022060207215957187_j_popets-2022-0043_ref_026","unstructured":"[26] Xinjian Luo, Yuncheng Wu, Xiaokui Xiao, and Beng Chin Ooi. Feature inference attack on model predictions in vertical federated learning. arXiv preprint arXiv:2010.10152, 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_027","unstructured":"[27] H Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, et al. Communication-efficient learning of deep networks from decentralized data. arXiv preprint arXiv:1602.05629, 2016."},{"key":"2022060207215957187_j_popets-2022-0043_ref_028","unstructured":"[28] Fan Mo, Anastasia Borovykh, Mohammad Malekzadeh, Hamed Haddadi, and Soteris Demetriou. Layer-wise characterization of latent information leakage in federated learning. arXiv preprint arXiv:2010.08762, 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_029","unstructured":"[29] Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y Ng. Reading digits in natural images with unsupervised feature learning. CiteSeerX, 2011."},{"key":"2022060207215957187_j_popets-2022-0043_ref_030","doi-asserted-by":"crossref","unstructured":"[30] Anastasia Pustozerova and Rudolf Mayer. Information leaks in federated learning. In Proceedings of the Network and Distributed System Security Symposium, 2020.10.14722\/diss.2020.23004","DOI":"10.14722\/diss.2020.23004"},{"key":"2022060207215957187_j_popets-2022-0043_ref_031","unstructured":"[31] Jia Qian and Lars Kai Hansen. What can we learn from gradients? arXiv preprint arXiv:2010.15718, 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_032","doi-asserted-by":"crossref","unstructured":"[32] Reza Shokri and Vitaly Shmatikov. Privacy-Preserving Deep Learning. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS \u201915, pages 1310\u2014-1321, New York, NY, USA, 2015. Association for Computing Machinery.10.1145\/2810103.2813687","DOI":"10.1145\/2810103.2813687"},{"key":"2022060207215957187_j_popets-2022-0043_ref_033","unstructured":"[33] Yusuke Tsuzuku, Hiroto Imachi, and Takuya Akiba. Variance-based gradient compression for efficient distributed deep learning. arXiv preprint arXiv:1802.06058, 2018."},{"key":"2022060207215957187_j_popets-2022-0043_ref_034","doi-asserted-by":"crossref","unstructured":"[34] Aidmar Wainakh, Till M\u00fc\u00dfig, Tim Grube, and Max M\u00fchlh\u00e4user. Label leakage from gradients in distributed machine learning. In 2021 IEEE 18th Annual Consumer Communications & Networking Conference (CCNC), pages 1\u20134. IEEE, 2021.10.1109\/CCNC49032.2021.9369498","DOI":"10.1109\/CCNC49032.2021.9369498"},{"key":"2022060207215957187_j_popets-2022-0043_ref_035","doi-asserted-by":"crossref","unstructured":"[35] Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. Beyond inferring class representatives: User-level privacy leakage from federated learning. In IEEE INFOCOM 2019-IEEE Conference on Computer Communications, pages 2512\u20132520. IEEE, 2019.10.1109\/INFOCOM.2019.8737416","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"2022060207215957187_j_popets-2022-0043_ref_036","doi-asserted-by":"crossref","unstructured":"[36] Wenqi Wei, Ling Liu, Margaret Loper, Ka-Ho Chow, Mehmet Emre Gursoy, Stacey Truex, and Yanzhao Wu. A framework for evaluating client privacy leakages in federated learning. In European Symposium on Research in Computer Security, pages 545\u2013566. Springer, 2020.10.1007\/978-3-030-58951-6_27","DOI":"10.1007\/978-3-030-58951-6_27"},{"key":"2022060207215957187_j_popets-2022-0043_ref_037","doi-asserted-by":"crossref","unstructured":"[37] Jingwen Zhang, Jiale Zhang, Junjun Chen, and Shui Yu. Gan enhanced membership inference: A passive local attack in federated learning. In ICC 2020-2020 IEEE International Conference on Communications (ICC), pages 1\u20136. IEEE, 2020.10.1109\/ICC40277.2020.9148790","DOI":"10.1109\/ICC40277.2020.9148790"},{"key":"2022060207215957187_j_popets-2022-0043_ref_038","unstructured":"[38] Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. idlg: Improved deep leakage from gradients. arXiv preprint arXiv:2001.02610, 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_039","unstructured":"[39] Huafei Zhu, Zengxiang Li, Merivyn Cheah, and Rick Siow Mong Goh. Privacy-preserving weighted federated learning within oracle-aided mpc framework. arXiv preprint arXiv:2003.07630, 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_040","unstructured":"[40] Junyi Zhu and Matthew Blaschko. R-gap: Recursive gradient attack on privacy. arXiv preprint arXiv:2010.07733, 2020."},{"key":"2022060207215957187_j_popets-2022-0043_ref_041","unstructured":"[41] Ligeng Zhu, Zhijian Liu, and Song Han. Deep leakage from gradients. In Advances in Neural Information Processing Systems, pages 14747\u201314756, 2019."}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2022-0043","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:32:03Z","timestamp":1658334723000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2022\/popets-2022-0043.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,3]]},"references-count":41,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,3,3]]},"published-print":{"date-parts":[[2022,4,1]]}},"alternative-id":["10.2478\/popets-2022-0043"],"URL":"https:\/\/doi.org\/10.2478\/popets-2022-0043","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,3]]}}}