acceptodds
Under review as a conference paper at ICLR 2027

TIGER: Inverting Multimodal Transformer Gradients via Embedding-Subspace Distance Optimization

Abstract

Federated learning (FL) allows multiple clients to jointly train a shared model by sending gradient updates to a central server while keeping their raw inputs local. Gradient inversion attacks, however, have shown that these updates can leak enough information to reconstruct client inputs. For transformers, though, existing attacks fall short in some of the following ways: they scale poorly to realistic model sizes, larger inputs, or non-causal attention; they require an enumerable vocabulary of token embeddings, preventing the recovery of continuous non-textual inputs; or they are brittle under numerical noise, e.g., from quantization or Differential Privacy (DP). In this paper, we introduce TIGER, a continuous gradient inversion attack that exploits the natural low-rank structure of attention gradients. Its novel objective aligns the features of dummy inputs across layers with the low-rank gradient subspaces, resulting in a single framework that recovers text from both causal and bidirectional attention models and, for the first time, multimodal inputs. On settings featuring bidirectional attention, TIGER substantially improves reconstruction quality over prior work and can recover images at roughly 720p resolution in the multimodal setting. On causal models, TIGER is significantly more robust than prior attacks, enabling accurate reconstructions even under quantization and DP-style defenses. Overall, TIGER uncovers further privacy vulnerabilities in LLMs, underscoring the need for stronger defenses in deployed FL systems.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.