TIGER: Inverting Multimodal Transformer Gradients via Embedding-Subspace Distance Optimization
Abstract
Federated learning (FL) allows multiple clients to jointly train a shared model by sending gradient updates to a central server while keeping their raw inputs local. Gradient inversion attacks, however, have shown that these updates can leak enough information to reconstruct client inputs. For transformers, though, existing attacks fall short in some of the following ways: they scale poorly to realistic model sizes, larger inputs, or non-causal attention; they require an enumerable vocabulary of token embeddings, preventing the recovery of continuous non-textual inputs; or they are brittle under numerical noise, e.g., from quantization or Differential Privacy (DP). In this paper, we introduce TIGER, a continuous gradient inversion attack that exploits the natural low-rank structure of attention gradients. Its novel objective aligns the features of dummy inputs across layers with the low-rank gradient subspaces, resulting in a single framework that recovers text from both causal and bidirectional attention models and, for the first time, multimodal inputs. On settings featuring bidirectional attention, TIGER substantially improves reconstruction quality over prior work and can recover images at roughly 720p resolution in the multimodal setting. On causal models, TIGER is significantly more robust than prior attacks, enabling accurate reconstructions even under quantization and DP-style defenses. Overall, TIGER uncovers further privacy vulnerabilities in LLMs, underscoring the need for stronger defenses in deployed FL systems.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.