2021
Gradient Disaggregation: Breaking Privacy in Federated Learning by Reconstructing the User Participant Matrix
ICML 2021oral
We show that aggregated model updates in federated learning may be insecure. An untrusted central server may disaggregate user updates from sums of updates across participants given repeated observations, enabling the server to recover privileged information about individual users’ private training…