Seeing the Forest through the Trees: Data Leakage from Partial Transformer Gradients

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Weijun, Xu, Qiongkai, Dras, Mark
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916422611894272
author Li, Weijun
Xu, Qiongkai
Dras, Mark
author_facet Li, Weijun
Xu, Qiongkai
Dras, Mark
contents Recent studies have shown that distributed machine learning is vulnerable to gradient inversion attacks, where private training data can be reconstructed by analyzing the gradients of the models shared in training. Previous attacks established that such reconstructions are possible using gradients from all parameters in the entire models. However, we hypothesize that most of the involved modules, or even their sub-modules, are at risk of training data leakage, and we validate such vulnerabilities in various intermediate layers of language models. Our extensive experiments reveal that gradients from a single Transformer layer, or even a single linear component with 0.54% parameters, are susceptible to training data leakage. Additionally, we show that applying differential privacy on gradients during training offers limited protection against the novel vulnerability of data disclosure.
format Preprint
id arxiv_https___arxiv_org_abs_2406_00999
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Seeing the Forest through the Trees: Data Leakage from Partial Transformer Gradients
Li, Weijun
Xu, Qiongkai
Dras, Mark
Machine Learning
Computation and Language
Cryptography and Security
I.2.7; I.2.11
Recent studies have shown that distributed machine learning is vulnerable to gradient inversion attacks, where private training data can be reconstructed by analyzing the gradients of the models shared in training. Previous attacks established that such reconstructions are possible using gradients from all parameters in the entire models. However, we hypothesize that most of the involved modules, or even their sub-modules, are at risk of training data leakage, and we validate such vulnerabilities in various intermediate layers of language models. Our extensive experiments reveal that gradients from a single Transformer layer, or even a single linear component with 0.54% parameters, are susceptible to training data leakage. Additionally, we show that applying differential privacy on gradients during training offers limited protection against the novel vulnerability of data disclosure.
title Seeing the Forest through the Trees: Data Leakage from Partial Transformer Gradients
topic Machine Learning
Computation and Language
Cryptography and Security
I.2.7; I.2.11
url https://arxiv.org/abs/2406.00999