acceptodds
Under review as a conference paper at ICLR 2027

No More Guessing: a Verifiable Gradient Inversion Attack in Federated Learning

Abstract

Existing gradient inversion attacks in federated learning can fail to disentangle aggregated batches and generally lack an intrinsic mechanism to certify reconstruction success. In vision and language domains, an attacker may rely on human inspection to assess reconstruction plausibility, but this can be costly and may limit attack efficacy and scalability under tight time constraints. For numerical tabular records, however, human inspection provides no comparable means of assessing reconstruction plausibility. We propose a verifiable gradient inversion attack (VGIA) that provides explicit certificates for record isolation and reconstruction. VGIA exploits the geometry of fully connected layers by interpreting activation boundaries as hyperplanes that partition the input space. It then applies an algebraic subspace test to detect when a hyperplane-delimited region contains exactly one record. Once a single record has been certified, our method analytically recovers the input features and uses lightweight optimization to reconstruct targets. Certified regions are then removed from further exploration, allowing VGIA to adaptively allocate subsequent hyperplane queries to unresolved regions. Experiments on tabular and image benchmarks demonstrate exact recovery under large batch sizes in regimes where prior methods fail or cannot assess fidelity. Thanks to its adaptive search strategy, VGIA also requires fewer attack rounds than previous approaches.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.