acceptodds
Under review as a conference paper at ICLR 2027

Adaptive Sparse Support as a Calibration-Dependent Label Channel in Split Learning

Abstract

Sparse gradients are usually discussed in terms of the values they retain. In split learning, however, the coordinates chosen for transmission can themselves reveal the client's label. We study when this support channel is exploitable and how it interacts with the aligned values. Across our experiments, label decoding is strong when the server has labeled calibration messages from the same checkpoint or training lineage, but it largely collapses across independent initializations. Our experiments also overturn our initial theoretical explanation. On Diamonds, same-label cross-fit fidelity is negative in every seed even though ordinary support decoding under the natural class prior reaches (balanced ); the attack is instead driven by class-conditional coordinate frequencies. A decoder-free test based on one auxiliary-selected coordinate gives 95% lower bounds of , , and bits on Digits, Synthetic-10, and Diamonds. At epoch 48 on compact CIFAR-10, support decoding remains and joint decoding . Data-independent supports close the support channel at small measured utility cost, yet values remain predictive in every useful-utility trainer we test. Support is therefore an additional privacy risk, not the whole leakage story. Our audit covers support and values for the declared row-wise sparse backward message, not the complete training transcript.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.