Title: Gradient Inversion Attacks: from Image Classification to Tabular Diffusion
Abstract: Federated learning guarantees that raw records never leave the silo and that only updates are shared.
However, several years of work has shown that it is possible to reconstruct private training samples directly from shared updates. The presentation will cover how gradient inversion works and what governs whether it succeeds: what stays unknown besides the data, how many records share one update, and what prior information the attacker can lean on.
On the way, we will discuss our own contributions to that research line, included our most recent result, GOLIATH, the first gradient inversion attack on tabular diffusion models.
Short bio: Jérémie Decouchant is an Assistant Professor at TU Delft, specializing in the design of robust distributed systems and algorithms. His research focuses on developing mechanisms to prevent, tolerate, and detect attacks, as well as defenses for adversarial multi-party environments. He applies these principles of dependable computing to federated and decentralized learning systems, with the goal of making them more secure, robust, and trustworthy.