Close Menu
Ztoog
    What's Hot
    The Future

    Starlink Mini Dish Release Appears to Be Imminent as New Images Surface

    AI

    Perception Fairness – Google Research Blog

    Mobile

    Google may have accidentally revealed when Apple will add RCS to iPhones

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      What is Project Management? 5 Best Tools that You Can Try

      Operational excellence strategy and continuous improvement

      Hannah Fry: AI isn’t as powerful as we think

      FanDuel goes all in on responsible gaming push with new Play with a Plan campaign

      Gettyimages.com Is the Best Website on the Internet Right Now

    • Technology

      Iran war: How could it end?

      Democratic senators question CFTC staffing cuts in Chicago enforcement office

      Google’s Cloud AI lead on the three frontiers of model capability

      AMD agrees to backstop a $300M loan from Goldman Sachs for Crusoe to buy AMD AI chips, the first known case of AMD chips used as debt collateral (The Information)

      Productivity apps failed me when I needed them most

    • Gadgets

      macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

      Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

      POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

      The Mission: Impossible of SSDs has arrived with a fingerprint lock

      6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    • Mobile

      Android’s March update is all about finding people, apps, and your missing bags

      Watch Xiaomi’s global launch event live here

      Our poll shows what buyers actually care about in new smartphones (Hint: it’s not AI)

      Is Strava down for you? You’re not alone

      The Motorola Razr FIFA World Cup 2026 Edition was literally just unveiled, and Verizon is already giving them away

    • Science

      Big Tech Signs White House Data Center Pledge With Good Optics and Little Substance

      Inside the best dark matter detector ever built

      NASA’s Artemis moon exploration programme is getting a major makeover

      Scientists crack the case of “screeching” Scotch tape

      Blue-faced, puffy-lipped monkey scores a rare conservation win

    • AI

      Online harassment is entering its AI era

      Meet NullClaw: The 678 KB Zig AI Agent Framework Running on 1 MB RAM and Booting in Two Milliseconds

      New method could increase LLM training efficiency | Ztoog

      The human work behind humanoid robots is being hidden

      NVIDIA Releases DreamDojo: An Open-Source Robot World Model Trained on 44,711 Hours of Real-World Human Video Data

    • Crypto

      Google paid startup Form Energy $1B for its massive 100-hour battery

      Ethereum Breakout Alert: Corrective Channel Flip Sparks Impulsive Wave

      Show Your ID Or No Deal

      Jane Street sued for alleged front-running trades that accelerated Terraform Labs meltdown

      Bitcoin Trades Below ETF Cost-Basis As MVRV Signals Mounting Pressure

    Ztoog
    Home » Overcoming Gradient Inversion Challenges in Federated Learning: The DAGER Algorithm for Exact Text Reconstruction
    AI

    Overcoming Gradient Inversion Challenges in Federated Learning: The DAGER Algorithm for Exact Text Reconstruction

    Facebook Twitter Pinterest WhatsApp
    Overcoming Gradient Inversion Challenges in Federated Learning: The DAGER Algorithm for Exact Text Reconstruction
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Federated studying allows collaborative mannequin coaching by aggregating gradients from a number of purchasers, thus preserving their personal knowledge. However, gradient inversion assaults can compromise this privateness by reconstructing the unique knowledge from the shared gradients. While efficient on picture knowledge, these assaults need assistance with textual content on account of their discrete nature, resulting in solely approximate restoration of small batches and brief sequences. This challenges LLMs in delicate fields like regulation and medication, the place privateness is essential. Despite federated studying’s promise, its privateness ensures are undermined by these gradient inversion assaults.

    Researchers from INSAIT, Sofia University, ETH Zurich, and LogicStar.ai have developed DAGER, an algorithm that exactly recovers whole batches of enter textual content. DAGER exploits the low-rank construction of self-attention layer gradients and the discrete nature of token embeddings to confirm token sequences in shopper knowledge, enabling actual batch restoration with out prior information. This technique, efficient for encoder and decoder architectures, makes use of heuristic search and grasping approaches, respectively. DAGER outperforms earlier assaults in velocity, scalability, and reconstruction high quality, recovering batches as much as dimension 128 on massive language fashions like GPT-2, LLaMa-2, and BERT.

    ✅ [Featured Article] LLMWare.ai Selected for 2024 GitHub Accelerator: Enabling the Next Wave of Innovation in Enterprise RAG with Small Specialized Language Models

    Gradient leakage assaults fall into two major varieties: honest-but-curious assaults, the place the attacker passively observes federated studying updates, and malicious server assaults, the place the attacker can modify the mannequin. This paper focuses on the tougher, honest-but-curious setting. Most analysis in this space targets picture knowledge, with text-based assaults usually requiring malicious adversaries or having limitations like brief sequences and small batches. DAGER overcomes these limitations by supporting massive batches and sequences for encoder and decoder transformers. It additionally works for token prediction and sentiment evaluation with out robust knowledge priors, demonstrating actual reconstruction for transformer-based language fashions.

    DAGER is an assault that recovers shopper enter sequences from gradients shared in transformer-based language fashions, specializing in decoder-only fashions for simplicity. It leverages the rank deficiency of the gradient matrix of self-attention layers to scale back the search area of potential inputs. Initially, DAGER identifies appropriate shopper tokens at every place by filtering out incorrect embeddings utilizing gradient subspace checks. Then, it recursively builds partial shopper sequences, verifying their correctness by way of subsequent self-attention layers. This two-stage course of permits DAGER to reconstruct the total enter sequences effectively by progressively extending partial sequences with verified tokens.

    The experimental analysis of DAGER demonstrates its superior efficiency in comparison with earlier strategies in varied settings. Tested on fashions like BERT, GPT-2, and Llama2-7B, and datasets resembling CoLA, SST-2, Rotten Tomatoes, and ECHR, DAGER constantly outperformed TAG and LAMP. DAGER achieved near-perfect sequence reconstructions, considerably surpassing baselines in decoder- and encoder-based fashions. Its effectivity was highlighted by lowered computation instances. The analysis additionally confirmed DAGER’s robustness to lengthy sequences and bigger fashions, sustaining excessive ROUGE scores even for bigger batch sizes, showcasing its scalability and effectiveness in various eventualities.

    In conclusion, the embedding dimension limits DAGER’s efficiency on decoder-based fashions, and actual reconstructions are unachievable when the token depend exceeds this dimension. Future analysis may discover DAGER’s resilience in opposition to protection mechanisms like DPSGD and its utility to extra advanced FL protocols. For encoder-based fashions, massive batch sizes pose computational challenges because of the progress of the search area, making actual reconstructions troublesome. Future work ought to deal with heuristics to scale back the search area. DAGER highlights the vulnerability of decoder-based LLMs to knowledge leakage, emphasizing the necessity for strong privateness measures in collaborative studying.


    Check out the Paper. All credit score for this analysis goes to the researchers of this mission. Also, don’t overlook to comply with us on Twitter. Join our Telegram Channel, Discord Channel, and LinkedIn Group.

    If you want our work, you’ll love our e-newsletter..

    Don’t Forget to hitch our 43k+ ML SubReddit


    Sana Hassan, a consulting intern at Marktechpost and dual-degree pupil at IIT Madras, is keen about making use of expertise and AI to deal with real-world challenges. With a eager curiosity in fixing sensible issues, he brings a recent perspective to the intersection of AI and real-life options.


    [Free AI Webinar] ‘How to Build Personalized Marketing Chatbots (Gemini vs LoRA)’.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    AI

    Online harassment is entering its AI era

    AI

    Meet NullClaw: The 678 KB Zig AI Agent Framework Running on 1 MB RAM and Booting in Two Milliseconds

    AI

    New method could increase LLM training efficiency | Ztoog

    AI

    The human work behind humanoid robots is being hidden

    AI

    NVIDIA Releases DreamDojo: An Open-Source Robot World Model Trained on 44,711 Hours of Real-World Human Video Data

    AI

    Personalization features can make LLMs more agreeable | Ztoog

    AI

    AI is already making online crimes easier. It could get much worse.

    AI

    NVIDIA Researchers Introduce KVTC Transform Coding Pipeline to Compress Key-Value Caches by 20x for Efficient LLM Serving

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    The Future

    Japan: Scientists developing drug to regrow teeth, trials to begin in July 2024

    Scientists in Japan are working to realise the dream of each dentist to revolutionise the…

    Technology

    Total War Pharaoh sees permanent price drop and partial refunds two months after launch

    A sizzling potato: Creative Assembly is now acknowledging that it has had a tough previous…

    Crypto

    Bitcoin Daily Chart Signals Impending Sell-Off, Analyst Says

    Popular crypto analyst Ali Martinez has painted a damaging image of Bitcoin’s potential worth trajectory…

    Science

    Experimental antibiotic kills deadly superbug, opens whole new class of drugs

    Enlarge / This Scanning Electron Microscope picture depicts a number of clusters of cardio Gram-negative,…

    Technology

    The best Nothing OS 2.5 features on the Nothing Phone 2

    (*2*)Rita El Khoury / Android AuthorityPublicity stunts like the Nothing Chats drama aren’t a assured…

    Our Picks
    The Future

    Ausdroid Reviews: Moto G84 5G – where beauty and brains come together

    Mobile

    iPhone Air impresses with durability and almost matches the iPhone 17 Pro

    Gadgets

    This introduction to cybersecurity is only $50 for a short time

    Categories
    • AI (1,560)
    • Crypto (1,826)
    • Gadgets (1,870)
    • Mobile (1,910)
    • Science (1,939)
    • Technology (1,862)
    • The Future (1,716)
    Most Popular
    Crypto

    Buying frenzy for Solana Mobile’s second phone drives preorders sky-high

    The Future

    Stephen Amell Admits His SAG Strike Comments Were Misguided

    AI

    Perception Fairness – Google Research Blog

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2026 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.